Junglewise Threat Intelligence

CVE-2026-79216: Google Chrome buffer overflow in Blink renderer

CVE-2026-79216 · Severity: high · CVSS 7.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser relied upon by billions of users. A buffer overflow vulnerability in Blink (Chrome's rendering engine) could allow an attacker who has already compromised the renderer process to execute arbitrary code within the browser's sandbox, potentially leading to further system compromise or data theft.

Technical details

A buffer overflow vulnerability exists in Blink, the rendering engine used by Google Chrome. The vulnerability can be triggered via a specially crafted HTML page and requires the attacker to have already compromised the renderer process. Successful exploitation allows arbitrary code execution within the browser's sandbox isolation boundary. The vulnerability affects Chrome versions prior to 152.0.7977.65 and was patched in that release. Attack vector is network-based but requires prior renderer compromise, making this a post-exploitation concern rather than a direct remote code execution path.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Announced in Chrome 152 stable release
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats