PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-79008 Google CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:56.537Z and has not been modified since then. This vulnerability affects Google Chrome on Android, particularly versions prior to 152.0.7977.65. The vulnerability's impact includes potential code execution outside the sandbox, emphasizing the need for immediate mitigation. Users of Google Chrome on Android should update to the latest version to mitigate potential risks. This includes administrators responsible for managing Google Chrome deployments on Android devices, as well as individual users who rely on Google Chrome for browsing.

Vendor
Google
Product
Chrome
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-08-26
Advisory published
2026-08-25
Advisory updated
2026-08-26

Who should care

Users of Google Chrome on Android, particularly those who may be targeted by remote attackers, should update to the latest version to mitigate potential risks. This includes administrators responsible for managing Google Chrome deployments on Android devices, as well as individual users who rely on Google Chrome for browsing. Ensuring the latest version is installed is crucial to preventing potential exploitation of this vulnerability. Additionally, security teams should review and verify the vulnerability's impact on their organization's assets and implement compensating controls if necessary.

Technical summary

Improper input validation in GPU in Google Chrome on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. This vulnerability affects Google Chrome on Android, particularly versions prior to 152.0.7977.65. The vulnerability's impact includes potential code execution outside the sandbox, emphasizing the need for immediate mitigation.

Defensive priority

Medium severity vulnerability in Google Chrome on Android, requiring immediate attention due to potential code execution outside the sandbox.

Recommended defensive actions

  • Verify and apply the latest Google Chrome update on Android to 152.0.7977.65 or later.
  • Restrict access to untrusted HTML pages.
  • Monitor Google Chrome for any subsequent updates or advisories related to this vulnerability.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence from official sources, including NVD and CVE Program records, indicates a medium severity vulnerability in Google Chrome on Android. Details are limited, and further verification is necessary. The CVE record was published on 2026-08-25T21:17:56.537Z and has not been modified since then. Additional review of Google Chrome's security advisories and Android-specific vulnerability management is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-79008 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-79008

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-79008 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79008

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.