CVE-2026-79202
8.8Google · Chrome
A use after free vulnerability exists in the Chromecast component of Google Chrome, which could allow a remote attacker to execute arbitrary code.
Executive summary
A high severity use after free vulnerability in the Google Chrome Chromecast component poses a significant risk of arbitrary code execution for unauthenticated remote attackers.
Vulnerability
This is a use after free vulnerability affecting the Chromecast implementation within the browser. An attacker can exploit this via a specifically crafted web page, requiring user interaction to execute arbitrary code.
Business impact
With a CVSS score of 8.8, this vulnerability presents a serious threat to organizational security. Successful exploitation could compromise the confidentiality, integrity, and availability of the host system, leading to potential data breaches.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.65 or later to resolve the vulnerability.
Proactive Monitoring: Monitor for unusual network or process activity related to the browser's media or casting components.
Compensating Controls: Ensure that browser-based security policies are strictly enforced and that users are discouraged from visiting untrusted websites.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for high-impact compromise, immediate deployment of the latest Chrome version is essential. Security teams should ensure the update process is completed across all managed endpoints to mitigate this critical risk.