Junglewise Threat Intelligence

CVE-2026-79200: Google Chrome use after free in Aura

CVE-2026-79200 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser that protects users from malicious websites and code execution. A use-after-free vulnerability in the Aura component allows an attacker to execute arbitrary code outside the sandbox by tricking a user into visiting a specially crafted webpage, potentially compromising the entire system and accessing sensitive user data.

Technical details

The vulnerability is a use-after-free flaw in the Aura component of Google Chrome prior to version 152.0.7977.65. This vulnerability occurs when the Aura code attempts to access memory that has been previously freed, allowing memory corruption. An attacker can exploit this by crafting a malicious HTML page that, when loaded in Chrome, triggers the use-after-free condition. The attack requires only that a user visit the malicious webpage (no prior authentication required). Successful exploitation allows arbitrary code execution outside the Chrome sandbox, effectively bypassing browser security protections. The fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published in Chrome Stable Channel Update
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats