CVE-2026-79131 – Chrome
“Crafted web content or network traffic can break out of the browser sandbox and execute attacker-controlled code.”
Google Chrome 152 fixes 327 Critical and High-severity vulnerabilities across V8, ANGLE, Media, Views, Aura, ServiceWorker, WebGL, Safe Browsing, Extensions, Network, Bluetooth, FileSystem, Passwords, DevTools, and other components. CVE-2026-79090 has a CVSS score of 9.8, Critical severity. Most of the remaining critical issues have CVSS scores of 9.6, while CVE-2026-79058 and CVE-2026-79148 are 9.1, Critical severity. CVE-2026-85046 has a CVSS score of 8.8, High severity. CVE-2026-85046 with a score of 8.8 is actively exploited.
Many of these vulnerabilities can lead to arbitrary code execution outside the browser sandbox, privilege escalation, memory corruption, or security-control bypass through crafted HTML content or malicious extensions. CVE-2026-85046 is listed as actively exploited and affects Chrome prior to 152.0.7977.82. The remaining listed issues affect earlier Chrome releases, primarily versions prior to 152.0.7977.65, with CVE-2026-76035 affecting versions prior to 151.0.7922.169.
CVE-2026-85046, CVE-2026-79090, CVE-2026-76035, CVE-2026-78900, CVE-2026-78904, CVE-2026-78909, CVE-2026-78939, CVE-2026-78945, CVE-2026-78948, CVE-2026-78951, CVE-2026-78964, CVE-2026-78985, CVE-2026-78989, CVE-2026-79012, CVE-2026-79019, CVE-2026-79026, CVE-2026-79043, CVE-2026-79047, CVE-2026-79052, CVE-2026-79056, CVE-2026-79064, CVE-2026-79078, CVE-2026-79091, CVE-2026-79111, CVE-2026-79128, CVE-2026-79130, CVE-2026-79131, CVE-2026-79138, CVE-2026-79140, CVE-2026-79149, CVE-2026-79150, CVE-2026-79188, CVE-2026-79189, CVE-2026-79200, CVE-2026-79232, CVE-2026-79235, CVE-2026-79257, CVE-2026-79275, CVE-2026-79290, CVE-2026-79058, CVE-2026-79148) 8.8, 9.8, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.1, 9.1
Key Details
- Affected Product
- Google Chrome
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-787