Executive brief
Google Chrome is a widely-used web browser that executes web pages and applications. A use-after-free vulnerability in the ServiceWorker component allows an attacker to execute arbitrary code outside the browser's security sandbox by tricking users into visiting a malicious webpage, potentially compromising user data and system security.
Technical details
The vulnerability is a use-after-free bug in Chrome's ServiceWorker implementation, a mechanism that allows web pages to cache content and work offline. The flaw allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page; no authentication or user interaction beyond visiting the malicious page is required. The attack vector is network-based and affects Chrome versions prior to 152.0.7977.65. This vulnerability was patched in Chrome 152.0.7977.65/64, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Public disclosure via Chrome Releases blog
- 2026-08-25: patched: Chrome 152.0.7977.65 released with fix