Executive brief
Google Chrome is a web browser used by billions of people worldwide. A use-after-free vulnerability in the Chromecast component allowed an attacker who compromised the browser's rendering process to execute arbitrary code outside the security sandbox, potentially gaining full control of the system. This required the renderer process to already be compromised but could lead to complete system compromise.
Technical details
A use-after-free vulnerability exists in the Chromecast component of Google Chrome prior to version 152.0.7977.65. The vulnerability is triggered by a crafted HTML page that causes freed memory to be accessed. An attacker who has already compromised the renderer process can exploit this flaw to escape the sandbox and execute arbitrary code with full system privileges. The vulnerability was patched in Chrome 152.0.7977.65 for Windows and Mac (152.0.7977.64 for Linux). Google assigned this Critical severity per Chromium security guidelines.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)
- 2026-05-26: reported