Chrome 152 Critical sandbox-escape flaws (CVE-2026-79290, CVE-2026-79282)
Google's Stable Channel Update for Desktop (25 August 2026) promotes Chrome 152 and ships 152.0.7977.64 on Linux and 152.0.7977.64/.65 on Windows and Mac. Among Critical fixes, CVE-2026-79290 is a use-after-free in Aura that Google rates Critical and says can let a remote attacker run code outside the browser sandbox via a crafted HTML page (fixed prior to 152.0.7977.65). CVE-2026-79282 is a Critical use-after-free in ANGLE (reported by Goodluck). WA SOC shared advisory 20260831001 (31 August, TLP:CLEAR) points operators at this Chrome update for Windows, macOS and Linux prior to 152.0.7977.65, rates the Critical issues CVSS 9.6, and says it has not received reports of exploitation on Western Australian Government networks at the time of writing. WASOC's advisory table display text for the second CVE does not match its NVD href (CVE-2026-79282); this card follows the Google release notes and that href. Patch promptly to the fixed Chrome 152 builds.
- Product
- Google Chrome
- Versions
- Prior to 152.0.7977.65 (Win/Mac); Linux build 152.0.7977.64 in the same release
- CVSS
- (CVSS 3.1, WASOC)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - Exploited in Australia?
- no
- Patch to
- 152.0.7977.65 (Windows/Mac) / 152.0.7977.64 (Linux) or later
Primary: Chrome Releases (25 Aug 2026) · Vendor: WA SOC 20260831001 (31 Aug) · CVE: CVE-2026-79290, CVE-2026-79282 · CVE-2026-79290
