Junglewise Threat Intelligence

CVE-2026-79121: Google Chrome improper input validation in Chromecast

CVE-2026-79121 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Chromecast integration contains an improper input validation vulnerability that could allow an attacker with access to the renderer process to escape the browser's security sandbox and execute arbitrary code. This affects Windows, Mac, and Linux systems and requires an attacker to first compromise the renderer process, potentially through a malicious webpage.

Technical details

This vulnerability is an improper input validation flaw in the Chromecast component of Google Chrome. The attack requires an attacker to have already compromised the renderer process (the sandboxed part of Chrome that executes web content), and then exploit the validation weakness via a crafted HTML page to break out of the sandbox and achieve code execution outside the sandbox boundary. The vulnerability was fixed in Chrome 152.0.7977.65 for Windows and Mac, and 152.0.7977.64 for Linux. Google assigned this a Critical severity rating in the Chromium security tracker.

Affected products

  • Google Chrome prior to 152.0.7977.65 (Windows/Mac); prior to 152.0.7977.64 (Linux)

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats