Description
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
In plain language
AI Act nowGoogle Chrome versions before 152.0.7977.65 can let an attacker run code on your computer if they have already taken over Chrome’s renderer process, via a crafted web page that abuses Chromecast—most small businesses won’t face this unless an attacker is already inside.
Use-after-free in the Chromecast component of Google Chrome prior to 152.0.7977.65 can be triggered by a specially crafted HTML page after an attacker compromises the renderer process, enabling arbitrary code execution outside the browser sandbox.
What to do now
- Check whether you run Google Chrome and whether it’s older than 152.0.7977.65.
- If it is older, update Google Chrome to 152.0.7977.65 or later.
- If you can’t update right away, disable or restrict Chromecast-related functionality in Chrome (as allowed by your IT policy) until you can update.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-79054 and every CVE in our database. Create a free account — no credit card required.
Create Free Account