Junglewise Threat Intelligence

CVE-2026-78899: Google Chrome use-after-free in V8

CVE-2026-78899 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's V8 JavaScript engine contained a use-after-free memory vulnerability that could allow attackers to execute arbitrary code within the browser's sandbox. An attacker could exploit this flaw by tricking a user into visiting a malicious webpage, potentially compromising the user's browsing session and access to sensitive information.

Technical details

A use-after-free vulnerability exists in V8, Chrome's JavaScript engine, where memory is accessed after it has been deallocated. The vulnerability can be triggered via a crafted HTML page delivered to a victim. While the attack occurs within the sandbox (limiting direct system impact), successful exploitation allows arbitrary code execution within the browser process. The flaw was present in Chrome versions prior to 152.0.7977.65 and is patched in Chrome 152.0.7977.65 and later. Attack vector is network-based, requiring only that a user visit a malicious webpage; no authentication or special privileges are required.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats