Junglewise Threat Intelligence

CVE-2026-79224: Google Chrome use after free in Chromecast

CVE-2026-79224 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users worldwide to access websites and web applications. This vulnerability is a memory safety defect (use-after-free) in Chrome's Chromecast component that allows an attacker who has already compromised the browser's rendering engine to break out of the browser sandbox and execute arbitrary code on the user's computer. Successful exploitation could lead to full system compromise with attacker gaining the ability to steal data, install malware, or take over the affected device.

Technical details

CVE-2026-79224 is a use-after-free vulnerability in the Chromecast component of Google Chrome. The vulnerability exists in Chrome versions prior to 152.0.7977.65, and was patched in version 152.0.7977.65. The attack requires a pre-existing compromise of the renderer process; the attacker then delivers a crafted HTML page to trigger the use-after-free condition in Chromecast. Successful exploitation allows the attacker to execute arbitrary code outside the browser sandbox with the privileges of the user running Chrome. The vulnerability was reported by Google to its own security team on 2026-05-27 and is marked as Critical severity by the Chromium project.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published in Chrome 152 stable release announcement
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats