CVE-2026-79224
massUse-after-free in Chromecast component of Google Chrome enables sandbox escape
Google Chrome versions prior to 152.0.7977.65 contain a use-after-free vulnerability (CWE-416) in the Chromecast component, rated Critical by Chromium. An attacker can trigger it by luring a user to a crafted HTML page (user interaction is required) and, after having compromised the renderer process, abuse the memory corruption to break out of Chrome's sandbox. Successful exploitation yields arbitrary code execution outside the sandbox, meaning code runs with the privileges of the browser's host process rather than the confined renderer, with high confidentiality, integrity and availability impact. All users running an affected Chrome build are potentially exposed, although the attack chain requires the attacker to already control the renderer process. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Update Google Chrome to 152.0.7977.65 or later immediately; since Chrome auto-updates, verify the running version via chrome://version or the About Chrome menu. Users of Chromium-based browsers that bundle the same code should apply their vendor's corresponding updates as they are released. Given the required prior renderer compromise, prompt patching and avoiding untrusted web pages remain the primary mitigations.
| Google Chrome | all versions prior to 152.0.7977.65 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.