Junglewise Threat Intelligence

CVE-2026-79052: Google Chrome use-after-free in Aura

CVE-2026-79052 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser that processes web content. A use-after-free vulnerability in Chrome's Aura component allows a remote attacker to execute arbitrary code outside the browser's security sandbox by crafting malicious HTML content. This could result in complete compromise of the user's system, including theft of sensitive data and installation of malware.

Technical details

CVE-2026-79052 is a use-after-free vulnerability in the Aura component of Google Chrome. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. No special authentication or preconditions are required; the attack is triggered simply by visiting a malicious web page. A use-after-free occurs when memory is accessed after it has been deallocated, potentially allowing an attacker to control execution flow or corrupt memory. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-79052 disclosed in Chrome 152 stable release
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65
  • 2026-05-28: other: Vulnerability reported to Google

References

Related threats