ZeroHour

CVE-2026-79290

mass

Use-after-free in Google Chrome Aura enables out-of-sandbox code execution

CVSS 3.1
9.6 critical
EPSS
<1%p31
Published
()
Modified
AI analysis

CVE-2026-79290 is a use-after-free memory corruption flaw (CWE-416) in the Aura component of Google Chrome, the windowing/UI layer of the Chromium browser stack. A remote attacker can trigger it by luring a user to open a crafted HTML page, an interaction requirement reflected in the CVSS vector (UI:R). Successful exploitation yields arbitrary code execution outside the Chrome sandbox, meaning the attacker escapes the browser's sandbox confinement and runs code with the privileges of the browser process on the host. All Chrome users running versions prior to 152.0.7977.65 are affected, and Google has assigned this flaw its Critical Chromium security severity. As of the current data there is no known public proof-of-concept exploit, it is not listed in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at only 0.4%, indicating exploitation activity is not yet widespread.

What to do: Update Google Chrome to 152.0.7977.65 or later immediately, verifying the installed version via chrome://settings/help, and keep automatic updates enabled; enterprise administrators should push the fixed build through their update-management policies. Until patched, treat untrusted links and HTML content with caution. Monitor Google's Chrome release channel for any follow-up fixes addressing this component.

Affected
Google Chromeall versions prior to 152.0.7977.65
Estimated exposure
mass≈3 billion+ users (Chrome holds roughly 60-65% of global browser usage) — Chrome's worldwide install base, derived from its dominant share of desktop and mobile browser traffic, places potential exposure in the billions of users, though the fraction of installations still on pre-152.0.7977.65 builds is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.