CVE-2026-79202

8.8

Google · Chrome

A use after free vulnerability exists in the Chromecast component of Google Chrome, which could allow a remote attacker to execute arbitrary code.

Executive summary

A high severity use after free vulnerability in the Google Chrome Chromecast component poses a significant risk of arbitrary code execution for unauthenticated remote attackers.

Vulnerability

This is a use after free vulnerability affecting the Chromecast implementation within the browser. An attacker can exploit this via a specifically crafted web page, requiring user interaction to execute arbitrary code.

Business impact

With a CVSS score of 8.8, this vulnerability presents a serious threat to organizational security. Successful exploitation could compromise the confidentiality, integrity, and availability of the host system, leading to potential data breaches.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later to resolve the vulnerability.

Proactive Monitoring: Monitor for unusual network or process activity related to the browser's media or casting components.

Compensating Controls: Ensure that browser-based security policies are strictly enforced and that users are discouraged from visiting untrusted websites.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for high-impact compromise, immediate deployment of the latest Chrome version is essential. Security teams should ensure the update process is completed across all managed endpoints to mitigate this critical risk.

More Google CVEs