Description
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Update Chrome
AI Analysis

Impact

A use‑after‑free bug exists in the Aura graphics layer of Google Chrome. When an attacker loads a specially crafted HTML page, the browser can free an object that is still referenced, allowing execution of arbitrary code outside the renderer sandbox. The flaw is classified as CWE‑416 and was rated as high severity by Chromium’s internal reviewers.

Affected Systems

This issue affects the Google Chrome desktop browser. Versions prior to 152.0.7977.65 are vulnerable. The fix is supplied in Chrome release 152.0.7977.65 and later.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity. The flaw remains a remote code‑execution vector that allows a crafted HTML page to free an object still referenced and execute code outside the renderer sandbox. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. While no public exploitation reports exist yet, the attack can be triggered by any untrusted HTML content, so systems running an affected Chrome version remain at significant risk until a patch is applied.

Generated by OpenCVE AI on August 26, 2026 at 03:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later by enabling automatic updates or downloading the latest installer from Google.
  • Confirm that automatic updates are enabled to receive future patches promptly.
  • If an immediate update is not possible, restrict browsing to known safe websites or use a web filter to block potentially malicious HTML content until the patch is applied.

Generated by OpenCVE AI on August 26, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Aura Use‑After‑Free Enables Remote Code Execution

Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:55:58.847Z

Reserved: 2026-08-25T06:12:06.592Z

Link: CVE-2026-79232

cve-icon Vulnrichment

Updated: 2026-08-26T00:19:21.560Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:17.413

Modified: 2026-08-31T18:15:31.563

Link: CVE-2026-79232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:00:04Z

Weaknesses