Junglewise Threat Intelligence

CVE-2026-79290: Google Chrome use after free in Aura

CVE-2026-79290 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used globally for accessing websites and web applications. A use-after-free vulnerability in Chrome's Aura component allows attackers to execute arbitrary code outside the browser's security sandbox by convincing a user to visit a malicious webpage, potentially compromising the entire system beyond the browser's protective boundaries.

Technical details

This vulnerability is a use-after-free in Aura, Chrome's user interface framework component. The flaw allows remote attackers to execute arbitrary code outside the sandbox via a specially crafted HTML page—no authentication or special user interaction beyond visiting the page is required. The attack vector is network-based: a user simply needs to navigate to or be redirected to a malicious website. Successful exploitation bypasses Chrome's sandbox isolation, granting an attacker the ability to access system resources and execute code with the privileges of the Chrome process. The vulnerability was patched in Chrome 152.0.7977.65.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published in Chrome 152 stable release announcement
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats