CVE-2026-79111

Google · Chrome

Google Chrome contains a high-severity input validation flaw in the Dawn component that allows remote code execution outside the sandbox via a crafted HTML page.

Executive summary

Google Chrome versions prior to 152.0.7977.65 are vulnerable to a critical remote code execution flaw that allows attackers to bypass sandbox protections.

Vulnerability

This vulnerability involves improper input validation within the Dawn component of Chrome, which can be triggered by an unauthenticated remote attacker through a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code outside the browser sandbox environment.

Business impact

The ability for an attacker to execute code outside the Chrome sandbox represents a severe threat to workstation security and corporate network integrity. With a CVSS score of 9.6, this vulnerability poses a critical risk of full system compromise, potential data exfiltration, and lateral movement within the environment. Prompt remediation is essential to prevent unauthorized access or system-wide infection.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected child processes originating from the Chrome browser.

Compensating Controls: Ensure that users are operating with the principle of least privilege, as this limits the potential impact of code execution occurring outside the browser sandbox.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the potential for sandbox escape, this issue must be prioritized for immediate deployment across the organization. Security teams should enforce the update to version 152.0.7977.65 or higher to eliminate the risk of arbitrary code execution.

More Google CVEs

Sources