CVE-2026-79033
8.8Google · Chrome
A vulnerability in Google Chrome DevTools allows remote attackers to execute arbitrary code within the sandbox via a crafted HTML page and social engineering.
Executive summary
A critical vulnerability in Google Chrome DevTools permits remote code execution within the sandbox, posing a significant risk to user data and system integrity.
Vulnerability
This flaw involves insufficient control flow management within the DevTools component, which can be triggered by an unauthenticated attacker using social engineering to lure a victim to a malicious HTML page.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code within the browser sandbox, potentially leading to unauthorized access to user data or system compromise. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires prompt attention to prevent potential data breaches or malicious software installation on end-user workstations.
Remediation
Immediate Action: Update all Google Chrome instances to version 152.0.7977.65 or later immediately to apply the necessary security patches.
Proactive Monitoring: Review security logs for anomalous browser behavior or unexpected network connections originating from browser-based processes.
Compensating Controls: Utilize endpoint protection software and browser-based security policies to block access to untrusted or newly registered domains that may host malicious HTML content.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should prioritize the deployment of the Google Chrome 152.0.7977.65 update across all managed environments to neutralize this threat. Given that this vulnerability requires social engineering, security awareness training should be reinforced to ensure users remain vigilant against suspicious web content.