Description
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a use-after-free condition in the Chromecast component of Google Chrome. When a remote attacker has managed to compromise the renderer process, they can supply a specially crafted HTML page that triggers the freed memory usage, enabling the attacker to execute arbitrary machine code outside of Chrome’s sandbox. The impact is full remote code execution on the host system, giving the attacker complete control over the affected machine. The weakness maps to CWE-416, a memory safety vulnerability that can lead to arbitrary code execution.

Affected Systems

Versions of Google Chrome released before the 152.0.7977.65 update are susceptible. The affected product is Google Chrome. The vulnerability is specifically tied to the Chromecast feature within the browser. Any environment running these earlier releases and enabling Chromecast could be impacted.

Risk and Exploitability

Based on the description, the likely attack vector is a crafted HTML page that reaches a renderer process that has already been compromised. The vulnerability is classified as high severity. The CVSS score of 9.6 underscores this high risk. The EPSS score is not available, and the exploit is not listed in CISA KEV, indicating no known widespread exploitation at this time. However, the attack requires the attacker to have already compromised the renderer process, which could be achieved via malicious web content or other vulnerabilities. Once renderer compromise is achieved, a crafted HTML page can trigger the use-after-free, allowing execution of arbitrary code outside the sandbox. The lack of a publicly tracked KEV instance does not diminish the risk, as the conditions for exploitation remain feasible in targeted or advanced threat scenarios.

Generated by OpenCVE AI on August 26, 2026 at 03:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later, which contains the fix for the use-after-free in Chromecast.
  • If an update cannot be applied immediately, disable the Chromecast feature or block access to it via browser policies to eliminate the attack surface.
  • Ensure Chrome’s sandboxing features are enabled and that renderer processes run with the least privileges necessary; consider restricting renderer permissions at the OS level; use advanced security settings such as Chrome Enterprise policies to limit extension capabilities.

Generated by OpenCVE AI on August 26, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 26 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chromecast Allowing Remote Code Execution via Crafted HTML Page

Wed, 26 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:56:07.492Z

Reserved: 2026-08-25T06:04:18.212Z

Link: CVE-2026-78939

cve-icon Vulnrichment

Updated: 2026-08-26T00:19:35.065Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:49.723

Modified: 2026-08-27T04:17:01.943

Link: CVE-2026-78939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:00:04Z

Weaknesses