CVE-2026-79188

Google · Chrome

A remote code execution vulnerability exists in the ANGLE graphics engine of Google Chrome, allowing attackers to bypass sandbox protections via a crafted HTML page.

Executive summary

A critical out of bounds write vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code outside the browser sandbox.

Vulnerability

This flaw is an out of bounds write vulnerability (CWE-787) located within the ANGLE graphics component of the browser. A remote, unauthenticated attacker can trigger this condition by enticing a user to visit a specially crafted HTML page, potentially leading to full system compromise.

Business impact

The ability to execute arbitrary code outside the browser sandbox represents a significant risk to organizational data and infrastructure. Given the high CVSS score of 9.6, this vulnerability could be leveraged to gain unauthorized access to the host system, exfiltrate sensitive user data, or deploy malicious payloads within the internal network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately to address the underlying memory corruption issue.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected process execution patterns that may indicate a successful sandbox escape attempt.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious browser-based processes and ensure that browser sandboxing features remain enabled and strictly enforced via group policy.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates a rapid deployment of the latest browser updates across all managed environments. Security teams should prioritize this patch to neutralize the risk of remote code execution and potential host-level compromise, as the browser remains a primary attack vector for modern threat actors.

More Google CVEs

Sources