CVE-2026-79189

Google · Chrome

An out of bounds write vulnerability in the ANGLE graphics engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.

Executive summary

Google Chrome versions prior to 152.0.7977.65 are susceptible to a critical out of bounds write vulnerability that could enable remote code execution.

Vulnerability

This is an out of bounds write vulnerability (CWE-787) located within the ANGLE component of the browser. The flaw can be triggered by an unauthenticated remote attacker through a maliciously crafted HTML page, potentially leading to code execution outside the browser sandbox.

Business impact

The vulnerability carries a CVSS score of 9.6, reflecting its capacity for full system compromise and significant impact on confidentiality, integrity, and availability. Successful exploitation allows an attacker to bypass critical security boundaries, posing a severe risk of data theft, malware deployment, or complete workstation takeover, which could lead to broader network compromise.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Security teams should monitor endpoint security logs for signs of anomalous browser behavior or unexpected process execution originating from the Chrome application.

Compensating Controls: Ensure that browser security features like site isolation remain enabled and consider deploying endpoint protection solutions capable of identifying and blocking malicious browser-based exploit patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity of this vulnerability and the potential for remote code execution, organizations must prioritize patching Chrome across all managed endpoints. Failure to update to the latest version leaves systems vulnerable to browser based attacks that could result in a total loss of system control.

More Google CVEs

Sources