Junglewise Threat Intelligence

CVE-2026-78937: Google Chrome use-after-free in Search on Android

CVE-2026-78937 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome on Android contains a use-after-free memory vulnerability in its Search component that allows remote attackers to execute arbitrary code outside the browser's sandbox. An attacker can exploit this flaw by tricking users into visiting a malicious HTML page, potentially enabling complete compromise of the device and access to sensitive user data.

Technical details

This is a use-after-free vulnerability in the Search component of Google Chrome on Android prior to version 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, requiring social engineering to trick the user into visiting the malicious page. The attack vector is network-based and does not require authentication or special user privileges beyond visiting a webpage. A patch is available in Chrome version 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed: CVE-2026-78937 disclosed in Chrome 152 release notes
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats