CVE-2026-79111
Google · Chrome
Google Chrome contains a high-severity input validation flaw in the Dawn component that allows remote code execution outside the sandbox via a crafted HTML page.
Executive summary
Google Chrome versions prior to 152.0.7977.65 are vulnerable to a critical remote code execution flaw that allows attackers to bypass sandbox protections.
Vulnerability
This vulnerability involves improper input validation within the Dawn component of Chrome, which can be triggered by an unauthenticated remote attacker through a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code outside the browser sandbox environment.
Business impact
The ability for an attacker to execute code outside the Chrome sandbox represents a severe threat to workstation security and corporate network integrity. With a CVSS score of 9.6, this vulnerability poses a critical risk of full system compromise, potential data exfiltration, and lateral movement within the environment. Prompt remediation is essential to prevent unauthorized access or system-wide infection.
Remediation
Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected child processes originating from the Chrome browser.
Compensating Controls: Ensure that users are operating with the principle of least privilege, as this limits the potential impact of code execution occurring outside the browser sandbox.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS severity and the potential for sandbox escape, this issue must be prioritized for immediate deployment across the organization. Security teams should enforce the update to version 152.0.7977.65 or higher to eliminate the risk of arbitrary code execution.