CVE-2026-79290
Description
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
In plain language
AI Act nowCVE-2026-79290 is a serious Chrome bug where a malicious web page can trick your browser into running harmful code outside Chrome’s safety sandbox; if you use Google Chrome, you should update to the fixed version urgently.
CVE-2026-79290 is a use-after-free memory flaw in Chrome’s Aura framework that can be triggered by a remote, unauthenticated attacker via a crafted HTML page, leading to arbitrary code execution outside the sandbox; fixed in Google Chrome 152.0.7977.65.
What to do now
- Check your Google Chrome version (Chrome menu → Help → About Google Chrome).
- If your version is older than 152.0.7977.65, update Chrome immediately to 152.0.7977.65 (or later).
- After updating, revisit your browsing protection settings (ensure Chrome’s safety features are enabled) and confirm the browser no longer reports the vulnerable version.
- If you cannot update right away, restrict who can browse to untrusted sites on that affected machine and avoid opening unknown links until the update is applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-79290 and every CVE in our database. Create a free account — no credit card required.
Create Free Account