Junglewise Threat Intelligence

CVE-2026-78909: Google Chrome use-after-free in Views

CVE-2026-78909 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a memory safety vulnerability in its Views component that allows attackers to execute arbitrary code outside the browser's security sandbox. An attacker can exploit this flaw by tricking a user into visiting a malicious webpage, potentially compromising the user's system and accessing sensitive data stored on the device.

Technical details

This vulnerability is a use-after-free memory safety defect in Chrome's Views component. The flaw allows a remote attacker to execute arbitrary code outside the sandbox boundary via a crafted HTML page, leveraging social engineering to trick a user into visiting the malicious content. The vulnerability was addressed in Chrome 152.0.7977.65 and later versions. The Chromium project rated this as Medium severity, though it has been assigned a CVSS v3 score of 9.6, reflecting the critical nature of out-of-sandbox code execution.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed

References

Related threats