Threat Advisory

Google Chrome Vulnerabilities Facilitate Unapproved Activities Triggered By Crafted Web Content

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Chrome, including critical use-after-free bugs that can let a malicious web page run code on your machine. Most of these flaws affect several browser components, including ANGLE, Aura, Views, Chromecast, and Safe Browsing. Any Chrome build before the latest fixed release is affected.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Chrome, including critical use-after-free bugs that can let a malicious web page run code on your machine. Most of these flaws affect several browser components, including ANGLE, Aura, Views, Chromecast, and Safe Browsing. Any Chrome build before the latest fixed release is affected.[emaillocker id="1283"]

CVE-2026-79282 (CVSS 9.6 — Critical): A use-after-free bug in the graphics layer can let an attacker craft a page that corrupts memory and hijacks the process.

CVE-2026-79290 (CVSS 9.6 — Critical): A use-after-free bug affects multiple browser parts, including ANGLE, Aura, Views, Chromecast, and Safebrowsing.

CVE-2026-79054 (CVSS 9.6 — Critical): A use-after-free vulnerability in the Chromecast component of Google Chrome allowed a remote attacker with a compromised renderer process to execute arbitrary code outside the sandbox through a specially crafted HTML page.

CVE-2026-79224 (CVSS 9.6 — Critical): A use-after-free vulnerability in the Chromecast component of Google Chrome allowed a remote attacker who compromised the renderer process to execute arbitrary code outside the sandbox through a specially crafted webpage.

CVE-2026-79052 (CVSS 9.6 — Critical): A critical use-after-free vulnerability in the Aura component of Google Chrome allowed a remote attacker to execute arbitrary code outside the sandbox through a specially designed content page.

CVE-2026-79150 (CVSS 9.6 — Critical): A critical use-after-free vulnerability in the Views component of Google Chrome on Mac allowed a remote attacker to execute arbitrary code outside the sandbox through a maliciously prepared resource.

CVE-2026-79012 (CVSS 9.6 — Critical): A critical use-after-free vulnerability in the Safe Browsing component of Google Chrome on Mac allowed a remote attacker using social engineering techniques to execute arbitrary code outside the sandbox through a maliciously prepared resource.

CVE-2026-79200 (CVSS 9.6 — Critical): A critical use-after-free vulnerability in the Aura component of Google Chrome allowed a remote attacker to execute arbitrary code outside the sandbox through a carefully constructed harmful input.

 

RECOMMENDATIONS:

  • We recommend you to update Google Chrome for Linux to version 152.0.7977.64 and for Windows, macOS to version 152.0.7977.64/.65 or later.

 

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/chrome-152-security-update/

[/emaillocker]
crossmenu