CVE-2026-79121

Google · Chrome

A critical improper input validation flaw in the Google Chrome Chromecast component allows remote attackers to achieve sandbox escape and execute arbitrary code via a malicious HTML page.

Executive summary

A critical vulnerability in Google Chrome allows remote attackers to bypass sandbox protections and achieve code execution through improper input validation in the Chromecast component.

Vulnerability

This is an improper input validation vulnerability (CWE-20) residing within the Chromecast component. The flaw allows an unauthenticated remote attacker, who has already compromised the renderer process, to execute arbitrary code outside the browser sandbox by enticing a user to view a crafted HTML page.

Business impact

The ability to execute arbitrary code outside the browser sandbox poses a significant risk to organizational endpoints, potentially leading to full system compromise and unauthorized data access. While the CVSS score is 8.3, the potential for sandbox escape elevates the technical risk significantly, as it provides an attacker with a foothold to bypass standard browser security boundaries.

Remediation

Immediate Action: Update all Google Chrome instances to version 152.0.7977.65 or later immediately to apply the vendor-provided patch.

Proactive Monitoring: Monitor endpoint security logs for signs of anomalous process spawning or unauthorized child process execution associated with the Google Chrome renderer.

Compensating Controls: Ensure that endpoint protection software is fully updated to detect exploit attempts targeting browser-based vulnerabilities, and encourage users to exercise caution when navigating to untrusted websites.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of sandbox escape vulnerabilities in web browsers, organizations should prioritize the deployment of the latest Google Chrome update across all managed workstations. Failure to patch this vulnerability leaves systems susceptible to remote code execution attacks initiated through routine web browsing activities.

More Google CVEs

Sources