Executive brief
Google Chrome's Aura display system contains a use-after-free vulnerability that allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page. An attacker could exploit this flaw to completely compromise a user's system, bypass Chrome's security protections, and gain full control over affected devices.
Technical details
This is a use-after-free vulnerability in the Aura component of Google Chrome prior to version 152.0.7977.65. The vulnerability can be triggered remotely through a crafted HTML page viewed in the browser, requiring no user authentication or system access. Successful exploitation allows an attacker to execute arbitrary code outside the sandbox, bypassing Chrome's primary security boundary. The flaw was discovered internally by Google and fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux), released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79232 disclosed; Chrome 152 released with fix
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)