PatchSiren cyber security CVE debrief
CVE-2026-79202 Google CVE debrief
A use-after-free vulnerability was reported in Google Chrome's Chromecast feature prior to version 152.0.7977.65. This issue could allow a remote attacker to execute arbitrary code within the sandbox by providing a crafted HTML page. The vulnerability has been identified as having a high severity rating. The vulnerability affects Google Chrome's Chromecast feature, which is a key component for streaming content from devices to Chrome. An attacker could exploit this vulnerability by tricking a user into visiting a maliciously crafted HTML page, potentially leading to arbitrary code execution within the sandbox. The severity of this issue is heightened due to the potential for code execution, emphasizing the importance of applying the patch to prevent exploitation. Evidence from official sources confirms the existence of this vulnerability, which has been addressed in Google Chrome version 152.0.7977.65.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-31
Who should care
Users of Google Chrome, particularly those who use the Chromecast feature, should apply the patch to prevent potential exploitation. System administrators responsible for managing Chrome installations in organizational environments should prioritize patching to mitigate risk.
Technical summary
The vulnerability is a use-after-free issue in the Chromecast feature of Google Chrome. This could allow a remote attacker to execute arbitrary code within the sandbox by providing a crafted HTML page. The issue has been addressed in Google Chrome version 152.0.7977.65.
Defensive priority
High priority due to potential for code execution within the sandbox
Recommended defensive actions
- Apply the official patch to update Google Chrome to version 152.0.7977.65 or later
- Restrict access to sensitive data and systems
- Monitor for suspicious activity
- Implement compensating controls such as network segmentation
- Conduct regular vulnerability assessments and penetration testing
Evidence notes
Evidence from official sources indicates a use-after-free vulnerability in Chromecast of Google Chrome prior to 152.0.7977.65. The CVE Program and NVD have analyzed this vulnerability, which has a CVSS score of 8.8 and is considered High severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79202 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79202
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79202 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79202
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/521285077
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.