CVE-2026-79200
massUse-after-free in Google Chrome Aura allows sandbox-escaping code execution
CVE-2026-79200 is a use-after-free memory corruption flaw in Aura, the UI/compositor layer of Google Chrome, and is rated Critical by Google. A remote attacker can trigger it by luring a user to a crafted HTML page, with no privileges or special network access required (CVSS AV:N/AC:L/PR:N/UI:R). Successful exploitation allows execution of arbitrary code outside the browser's security sandbox, meaning the attacker can compromise the host rather than just a tab. Any Chrome installation running a version prior to 152.0.7977.65 is affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates only about a 0.4% chance of exploitation within 30 days.
What to do: Update Chrome to version 152.0.7977.65 or later immediately and verify the running version via chrome://version. Enterprise administrators should force browser updates through their management tooling (e.g., Chrome Browser Cloud Management/WSUS-style repositories) and prioritize hosts with unmanaged or older installs. Until patched, treat visits to untrusted websites as a primary attack vector, since exploitation requires user navigation to a crafted page.
| google chrome | all versions prior to 152.0.7977.65 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.