CVE-2026-79210: Use after free in Google Chrome
Description
A use-after-free vulnerability exists in the Audio component of Google Chrome on Android versions prior to 152.0.7977.65. This flaw allows a remote attacker who has compromised the renderer process to execute arbitrary code outside the sandbox by delivering a crafted HTML page. The vulnerability has a high severity rating with a CVSS score of 8.3. The issue affects Chrome on Android before version 152.0.7977.65. There is no explicit vendor advisory text confirming patch availability, but the presence of a stable channel update announcement suggests a fix has been released.
CVSS v3.1
Score 8.3high
Affected software
Chrome
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-79210 is a use-after-free vulnerability in the Audio component of Google Chrome on Android. It allows remote code execution outside the sandbox if the attacker has compromised the renderer process and can deliver a crafted HTML page. The vulnerability is rated high severity with a CVSS 3.1 score of 8.3, reflecting network attack vector, high complexity, no privileges required, user interaction required, and complete confidentiality, integrity, and availability impact. The vulnerability affects versions prior to 152.0.7977.65. The vendor has published a stable channel update, indicating a fix is available.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code outside the sandbox on affected Chrome Android versions, potentially compromising confidentiality, integrity, and availability of the system. This requires the attacker to have compromised the renderer process and to trick the user into interacting with a crafted HTML page.
Mitigation Recommendations
A stable channel update for Google Chrome has been published by the vendor, indicating that a fix is available. Users and administrators should update Chrome on Android to version 152.0.7977.65 or later to remediate this vulnerability. Patch status is inferred from the vendor's stable channel update announcement; check the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-08-25T06:11:37.462Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html","vendor":"Google"}]
Threat ID: 6a8df9deacd9273b49ac7217
Added to database: 08/25/2026, 20:23:58 UTC
Last enriched: 09/09/2026, 22:22:09 UTC
Last updated: 10/08/2026, 06:48:19 UTC
Views: 30
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.