ZeroHour

CVE-2026-79121

mass

Sandbox Escape via Improper Input Validation in Google Chrome (Chromecast)

CVSS 3.1
8.3 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-79121 is an improper input validation flaw in the Chromecast component of Google Chrome that Google rates as a Critical Chromium security issue. It is triggered via a crafted HTML page, and the attacker must first have compromised the Chrome renderer process (typically with a separate renderer bug) before this flaw can be leveraged. Successfully exploiting it allows the attacker to break out of the Chrome sandbox and execute arbitrary code outside it, giving full process-level access on the victim's machine with the scope of the impact crossing the security boundary. Anyone running Google Chrome prior to 152.0.7977.65 is affected, spanning desktop and mobile installs where the casting feature ships by default. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.3%, so it is not currently known to be exploited in the wild.

What to do: Update Google Chrome to 152.0.7977.65 or later on all endpoints, using MDM/EDR reporting or managed-browser policies to verify fleet versions. Because exploitation requires a prior renderer-process compromise, treat this as a chainable privilege-escalation primitive and patch it promptly alongside any renderer bugs. There are no known workarounds beyond disabling casting or restricting untrusted web content, neither of which is practical, so patching is the primary mitigation.

Affected
google chromeall versions prior to 152.0.7977.65
Estimated exposure
mass≈3+ billion Chrome users (Chrome's global installed base; Chromecast/casting support ships by default) — Google Chrome is the world's dominant browser with an estimated 3-4 billion users and roughly 65% desktop market share, and the affected Chromecast functionality is present in default installs, so essentially the entire unpatched Chrome…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.