CVE-2026-79131
Google · Chrome
An out of bounds write vulnerability in the ANGLE component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical out of bounds write vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code and bypass sandbox protections.
Vulnerability
This is an out of bounds write flaw (CWE-787) within the ANGLE graphics engine. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution outside the browser sandbox.
Business impact
The CVSS score of 9.6 reflects the critical nature of this flaw, as it permits full system compromise through remote code execution. Successful exploitation can lead to total loss of confidentiality, integrity, and availability of the affected system, posing a severe threat to enterprise data security and operational stability.
Remediation
Immediate Action: Update all Google Chrome installations to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected child process spawning related to the Chrome executable.
Compensating Controls: While browser-level patches are the primary defense, ensure that robust endpoint detection and response (EDR) solutions are active to identify and block suspicious shellcode execution patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity and the potential for sandbox escape, this vulnerability represents a significant risk to all workstation environments. IT administrators must prioritize the rapid deployment of the updated version of Google Chrome to all managed devices to prevent potential exploitation.