Junglewise Threat Intelligence

CVE-2026-78939: Google Chrome use-after-free in Chromecast

CVE-2026-78939 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free vulnerability in its Chromecast component that could allow an attacker who has already compromised the browser's rendering engine to escape the security sandbox and run arbitrary code on the system. This would give attackers unrestricted access to the user's computer, including sensitive files, credentials, and the ability to install malware.

Technical details

A use-after-free vulnerability exists in the Chromecast component of Google Chrome prior to version 152.0.7977.65. The vulnerability requires the attacker to have first compromised the renderer process (achieved through methods like delivering malicious JavaScript on a webpage), then exploit the use-after-free to break out of the sandbox and achieve code execution with full system privileges. The attack is delivered via a crafted HTML page. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats