CVE-2026-79290
massUse-after-free in Google Chrome Aura enables out-of-sandbox code execution
CVE-2026-79290 is a use-after-free memory corruption flaw (CWE-416) in the Aura component of Google Chrome, the windowing/UI layer of the Chromium browser stack. A remote attacker can trigger it by luring a user to open a crafted HTML page, an interaction requirement reflected in the CVSS vector (UI:R). Successful exploitation yields arbitrary code execution outside the Chrome sandbox, meaning the attacker escapes the browser's sandbox confinement and runs code with the privileges of the browser process on the host. All Chrome users running versions prior to 152.0.7977.65 are affected, and Google has assigned this flaw its Critical Chromium security severity. As of the current data there is no known public proof-of-concept exploit, it is not listed in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at only 0.4%, indicating exploitation activity is not yet widespread.
What to do: Update Google Chrome to 152.0.7977.65 or later immediately, verifying the installed version via chrome://settings/help, and keep automatic updates enabled; enterprise administrators should push the fixed build through their update-management policies. Until patched, treat untrusted links and HTML content with caution. Monitor Google's Chrome release channel for any follow-up fixes addressing this component.
| Google Chrome | all versions prior to 152.0.7977.65 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.