Executive brief
Google Chrome's Media component failed to properly enforce security boundaries, allowing a remote attacker who had already compromised the browser's renderer process to escape the security sandbox and execute arbitrary code with system privileges. This could enable attackers to take complete control of a user's computer, steal sensitive data, or install malware.
Technical details
This vulnerability is a sandbox escape affecting Google Chrome prior to version 152.0.7977.65. The Media component improperly enforces behavioral workflow validation, allowing an attacker with control over the renderer process (through prior code execution or a separate renderer exploit) to craft malicious HTML that triggers logic allowing arbitrary code execution outside the sandbox. The attack requires an attacker to first compromise the renderer process but does not require user interaction beyond loading a crafted webpage. Google patched this in Chrome 152.0.7977.65 released on August 25, 2026. The Chromium project originally classified this as medium severity, but the sandbox escape nature and code execution impact warrant higher severity.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79083 fixed in Chrome 152.0.7977.65
- 2026-08-25: patched: Patch released in Chrome 152.0.7977.65 for Windows, Mac, and Linux