ZeroHour

CVE-2026-79200

mass

Use-after-free in Google Chrome Aura allows sandbox-escaping code execution

CVSS 3.1
9.6 critical
EPSS
<1%p31
Published
()
Modified
AI analysis

CVE-2026-79200 is a use-after-free memory corruption flaw in Aura, the UI/compositor layer of Google Chrome, and is rated Critical by Google. A remote attacker can trigger it by luring a user to a crafted HTML page, with no privileges or special network access required (CVSS AV:N/AC:L/PR:N/UI:R). Successful exploitation allows execution of arbitrary code outside the browser's security sandbox, meaning the attacker can compromise the host rather than just a tab. Any Chrome installation running a version prior to 152.0.7977.65 is affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates only about a 0.4% chance of exploitation within 30 days.

What to do: Update Chrome to version 152.0.7977.65 or later immediately and verify the running version via chrome://version. Enterprise administrators should force browser updates through their management tooling (e.g., Chrome Browser Cloud Management/WSUS-style repositories) and prioritize hosts with unmanaged or older installs. Until patched, treat visits to untrusted websites as a primary attack vector, since exploitation requires user navigation to a crafted page.

Affected
google chromeall versions prior to 152.0.7977.65
Estimated exposure
masson the order of billions of Chrome installations are affected until updated (Chrome has roughly 3 billion+ users) — Chrome is the world's dominant browser with roughly two-thirds of desktop market share and a multi-billion-user install base, so effectively all unpatched Chrome instances globally are exposed; per-user counts beyond the fixed version…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.