CVE-2026-79142: Buffer overflow in Google Chrome
Description
A buffer overflow vulnerability exists in the ANGLE component of Google Chrome on Android versions prior to 152.0.7977.65. This flaw allows a remote attacker to execute arbitrary code outside the browser sandbox by tricking a user into visiting a specially crafted HTML page. The vulnerability has a high severity rating with a CVSS score of 8.8. No confirmed exploits in the wild have been reported. The issue affects Android Chrome versions before 152.0.7977.65.
CVSS v3.1
Score 8.8high
Affected software
Chrome
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-79142 is a high-severity buffer overflow vulnerability in the ANGLE graphics engine used by Google Chrome on Android. It allows remote code execution outside the sandbox via a crafted HTML page. The vulnerability affects Chrome on Android versions prior to 152.0.7977.65. The CVSS 3.1 base score is 8.8, indicating high impact on confidentiality, integrity, and availability. The vendor has published an advisory but has not explicitly stated the remediation level or patch availability in the provided data.
Potential Impact
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code outside the sandbox on the affected device, potentially leading to full compromise of the browser process and access to user data or system resources. The high CVSS score reflects the critical nature of the impact on confidentiality, integrity, and availability.
Mitigation Recommendations
The vendor advisory link indicates a stable channel update for Chrome, implying a fix is available in version 152.0.7977.65. Users should update their Chrome on Android to version 152.0.7977.65 or later to remediate this vulnerability. Patch status is not explicitly confirmed in the advisory content provided, so users should verify the update details on the official Google Chrome release blog.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-08-25T06:10:21.965Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html","vendor":"Google"}]
Threat ID: 6a8df9d6acd9273b49ac70f3
Added to database: 08/25/2026, 20:23:50 UTC
Last enriched: 09/09/2026, 22:52:21 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 35
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.