ZeroHour

CVE-2026-79224

mass

Use-after-free in Chromecast component of Google Chrome enables sandbox escape

CVSS 3.1
8.3 high
EPSS
<1%p26
Published
()
Modified
AI analysis

Google Chrome versions prior to 152.0.7977.65 contain a use-after-free vulnerability (CWE-416) in the Chromecast component, rated Critical by Chromium. An attacker can trigger it by luring a user to a crafted HTML page (user interaction is required) and, after having compromised the renderer process, abuse the memory corruption to break out of Chrome's sandbox. Successful exploitation yields arbitrary code execution outside the sandbox, meaning code runs with the privileges of the browser's host process rather than the confined renderer, with high confidentiality, integrity and availability impact. All users running an affected Chrome build are potentially exposed, although the attack chain requires the attacker to already control the renderer process. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Update Google Chrome to 152.0.7977.65 or later immediately; since Chrome auto-updates, verify the running version via chrome://version or the About Chrome menu. Users of Chromium-based browsers that bundle the same code should apply their vendor's corresponding updates as they are released. Given the required prior renderer compromise, prompt patching and avoiding untrusted web pages remain the primary mitigations.

Affected
Google Chromeall versions prior to 152.0.7977.65
Estimated exposure
massorder of hundreds of millions to billions of installations (Chrome holds roughly 65% global browser market share, on the order of 3 billion users) — Chrome is the dominant desktop browser by market share with an install base measured in billions, so unpatched installations prior to auto-update propagation are plausibly in the hundreds of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.