CVE-2026-79231

8.8

Google · Chrome

A buffer overflow vulnerability in the Media component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity buffer overflow vulnerability in Google Chrome allows remote code execution through malicious web content, posing a significant risk to user systems.

Vulnerability

This is a buffer overflow (CWE-122) occurring within the browser's Media component. The vulnerability is exploitable by an unauthenticated remote attacker who can induce a user to visit a specially crafted HTML page.

Business impact

Successful exploitation allows an attacker to execute arbitrary code within the context of the browser sandbox, potentially leading to full system compromise if coupled with a sandbox escape. Given the CVSS score of 8.8, this vulnerability represents a high risk to organizational data integrity and system availability, particularly in environments where browser-based workflows are critical.

Remediation

Immediate Action: Update all installations of Google Chrome to version 152.0.7977.65 or later to resolve the underlying buffer overflow flaw.

Proactive Monitoring: Review web proxy and browser access logs for requests directed toward suspicious or untrusted domains that may attempt to deliver malicious HTML payloads.

Compensating Controls: Ensure that endpoint security solutions are active and up to date, as these may detect the execution of arbitrary code resulting from browser-based exploits.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to ensure all browser instances are patched. IT administrators should prioritize the deployment of the Google Chrome update across all workstations to mitigate the risk of remote code execution and potential system compromise.

More Google CVEs

Sources