Executive brief
Google Chrome's DevTools component contains a use-after-free memory vulnerability that allows attackers to execute arbitrary code within the browser's sandbox. An attacker can exploit this by tricking a user into installing a malicious Chrome extension, potentially leading to unauthorized access to sensitive data or complete compromise of the user's browser session.
Technical details
This is a use-after-free vulnerability in Chrome's DevTools component (CWE-416). The vulnerability allows a remote attacker to execute arbitrary code within the sandbox via a crafted Chrome extension. The attack vector involves social engineering to convince a user to install the malicious extension; no additional authentication or special privileges are required beyond user interaction. Exploitation results in arbitrary code execution within the Chrome sandbox. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-78944 disclosed and Chrome 152.0.7977.65 released with patch
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65