Description
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw (CWE-416) in Chrome’s Aura component, allowing a remote attacker to execute arbitrary code outside the sandbox by serving a specially crafted HTML page.

Affected Systems

Any installation of Google Chrome that runs version 152.0.7977.64 or earlier is affected.

Risk and Exploitability

Chromium reports the flaw with a CVSS score of 9.6, indicating critical severity. No exploitation probability is available, and it is not yet listed in CISA’s KEV catalog. The flaw can be leveraged by delivering a malicious web page, giving the attacker full control over a confirmed user’s machine without sandbox restrictions.

Generated by OpenCVE AI on August 26, 2026 at 03:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later, as distributed in the stable channel.
  • Ensure the update is propagated to all organizational installations to exclude the vulnerable code path.
  • Continuously monitor Chrome security advisories and apply subsequent patches without delay.

Generated by OpenCVE AI on August 26, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome's Aura Enables Remote Code Execution via Crafted HTML Page
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:56:10.528Z

Reserved: 2026-08-25T06:11:24.393Z

Link: CVE-2026-79200

cve-icon Vulnrichment

Updated: 2026-08-26T00:19:39.083Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:13.827

Modified: 2026-08-31T18:23:57.050

Link: CVE-2026-79200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:00:04Z

Weaknesses