Executive brief
Google Chrome's Chromecast component contains a use-after-free vulnerability that allows attackers to execute arbitrary code within the browser's sandboxed environment. An attacker can exploit this by crafting a malicious HTML page and tricking a user into visiting it. Successful exploitation could allow attackers to bypass browser security protections and potentially compromise user data or system integrity.
Technical details
This vulnerability is a use-after-free memory corruption bug in Chrome's Chromecast component. The flaw exists in Google Chrome versions prior to 152.0.7977.65 and is exploitable via a specially crafted HTML page delivered over the network. An attacker needs only to socially engineer a user into visiting a malicious website; no special privileges or authentication are required. Successful exploitation allows arbitrary code execution within the Chrome sandbox. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79202 disclosed in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65