CVE-2026-79121
Google · Chrome
A critical improper input validation flaw in the Google Chrome Chromecast component allows remote attackers to achieve sandbox escape and execute arbitrary code via a malicious HTML page.
Executive summary
A critical vulnerability in Google Chrome allows remote attackers to bypass sandbox protections and achieve code execution through improper input validation in the Chromecast component.
Vulnerability
This is an improper input validation vulnerability (CWE-20) residing within the Chromecast component. The flaw allows an unauthenticated remote attacker, who has already compromised the renderer process, to execute arbitrary code outside the browser sandbox by enticing a user to view a crafted HTML page.
Business impact
The ability to execute arbitrary code outside the browser sandbox poses a significant risk to organizational endpoints, potentially leading to full system compromise and unauthorized data access. While the CVSS score is 8.3, the potential for sandbox escape elevates the technical risk significantly, as it provides an attacker with a foothold to bypass standard browser security boundaries.
Remediation
Immediate Action: Update all Google Chrome instances to version 152.0.7977.65 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Monitor endpoint security logs for signs of anomalous process spawning or unauthorized child process execution associated with the Google Chrome renderer.
Compensating Controls: Ensure that endpoint protection software is fully updated to detect exploit attempts targeting browser-based vulnerabilities, and encourage users to exercise caution when navigating to untrusted websites.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of sandbox escape vulnerabilities in web browsers, organizations should prioritize the deployment of the latest Google Chrome update across all managed workstations. Failure to patch this vulnerability leaves systems susceptible to remote code execution attacks initiated through routine web browsing activities.