Description
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the Chromecast component of Google Chrome. It enables a remote attacker who can serve a crafted HTML page to execute arbitrary code inside the browser sandbox. This flaw is a classic memory‑safety issue (CWE‑416) that would allow an attacker to run code with the same privileges as the browser process.

Affected Systems

All installations of Google Chrome prior to build 152.0.7977.65 are affected. No other products or versions are listed as impacted.

Risk and Exploitability

No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the Chromium security team rated it High, with a CVSS score of 8.8. The attack requires an attacker to host a malicious page in a way that the user visits or a compromise that injects code into Chrome, then the crafted HTML triggers the use‑after‑free. Successful exploitation would give the attacker code execution with sandbox privileges, which could lead to privilege escalation or full system compromise if additional post‑exploitation techniques are applied.

Generated by OpenCVE AI on August 26, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to release 152.0.7977.65 or later, which contains the vendor‑supplied fix for the Chromecast use‑after‑free flaw.
  • If an immediate upgrade is not possible, disable the Chromecast feature by setting the relevant flag (chrome://flags) or using launch options to prevent the component from loading.
  • After applying the fix or disabling the feature, monitor browser activity for anomalous sandbox activity and review logs for signs of exploitation attempts.

Generated by OpenCVE AI on August 26, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chromecast Use-After-Free Enables Remote Code Execution

Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:56:03.285Z

Reserved: 2026-08-25T06:11:26.619Z

Link: CVE-2026-79202

cve-icon Vulnrichment

Updated: 2026-08-26T00:07:26.183Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:14.047

Modified: 2026-08-31T18:23:41.280

Link: CVE-2026-79202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T03:45:03Z

Weaknesses