Executive brief
Google Chrome is a web browser used by billions of people to access websites and web applications. A use-after-free memory vulnerability in Chrome's Views component could allow an attacker to execute malicious code with full system privileges outside the browser's security sandbox by tricking a user into visiting a specially crafted webpage. This could result in complete compromise of the user's computer, including theft of sensitive data, installation of malware, or unauthorized access to personal information.
Technical details
A use-after-free vulnerability exists in the Views UI framework component of Google Chrome prior to version 152.0.7977.65. The vulnerability occurs when memory is accessed after it has been freed, allowing attackers to corrupt heap data structures. The attack requires social engineering to trick a user into opening a malicious HTML page, making the attack vector network-based with user interaction required. Successful exploitation allows code execution outside the Chrome sandbox with no additional privileges required. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Chrome 152 stable release with fix
- 2026-08-25: advisory