Junglewise Threat Intelligence

CVE-2026-79182: Google Chrome improper input validation in Media

CVE-2026-79182 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's media handling component contains an improper input validation vulnerability that allows remote attackers to execute arbitrary code outside the browser's security sandbox through a specially crafted HTML page. This vulnerability bypasses Chrome's sandboxing protections, enabling attackers to gain full system access and compromise user data and system security. The vulnerability affects all Chrome versions prior to 152.0.7977.65 and requires only that a user visits a malicious webpage to be exploited.

Technical details

This vulnerability is an improper input validation flaw in Google Chrome's Media component that allows remote code execution outside the sandbox boundary. The root cause lies in insufficient validation of crafted media content within HTML pages, enabling attackers to trigger arbitrary code execution with the privileges of the Chrome process. The attack vector is network-based and requires user interaction (visiting a malicious website); no authentication is required. An attacker can achieve arbitrary code execution outside the sandbox, effectively compromising the entire system. The vulnerability was patched in Chrome version 152.0.7977.65 released on August 25, 2026, and patches are available for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows, Mac, and Linux

References

Related threats