CVE-2026-79073

8.8

Google · Chrome

Google Chrome contains an improper state validation vulnerability in the Parser component, which can be exploited by a remote attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution through the use of a specially crafted HTML page.

Vulnerability

This flaw involves improper state validation within the browser parser (CWE-754). It allows an unauthenticated remote attacker to execute arbitrary code within the browser sandbox by tricking a user into navigating to a malicious web page.

Business impact

The ability for an attacker to execute arbitrary code within the browser environment poses a significant risk to organizational endpoints. Successful exploitation could lead to full system compromise, the installation of malware, or unauthorized access to sensitive user data and credentials. Given the CVSS score of 8.8, this vulnerability is classified as high severity and requires immediate attention to prevent potential data breaches or lateral movement within the network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Review browser security logs for unusual navigation patterns and ensure that endpoint security software is configured to detect and block malicious web content.

Compensating Controls: Deploy endpoint protection platforms that utilize heuristic analysis to identify and neutralize malicious HTML or JavaScript content before it can be processed by the browser.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations must prioritize the deployment of the latest Chrome security updates across all managed devices to neutralize this threat. Given the potential for remote code execution, delaying the patch process exposes the environment to unnecessary risk and should be avoided.

More Google CVEs

Sources