CVE-2026-79240
8.8Google · Chrome
An out of bounds write vulnerability in the ANGLE component of Google Chrome on Windows allows remote code execution via a crafted HTML page.
Executive summary
A high severity out of bounds write vulnerability in Google Chrome on Windows allows a remote attacker to execute arbitrary code within the browser sandbox.
Vulnerability
This vulnerability involves an out of bounds write flaw within the ANGLE graphics engine component. The vulnerability is triggered when an unauthenticated remote attacker lures a user to visit a specifically crafted HTML page.
Business impact
Successful exploitation of this flaw allows a remote attacker to achieve arbitrary code execution within the context of the Chrome sandbox. Given the CVSS score of 8.8, this represents a significant risk to data confidentiality, integrity, and system availability, as browser-based attacks are a common vector for initial access and malware deployment.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately to resolve the vulnerable ANGLE component.
Proactive Monitoring: Monitor endpoint security logs for anomalous browser behavior or unexpected child process spawning related to the Chrome executable.
Compensating Controls: Ensure that Chrome's built-in sandbox protections are enabled and consider utilizing browser isolation solutions to contain potential threats from malicious web content.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a high risk due to the potential for remote code execution via common web browsing activities. Security administrators should prioritize the deployment of the 152.0.7977.65 update across all Windows workstations to ensure protection against this memory corruption flaw.