Junglewise Threat Intelligence

CVE-2026-78951: Google Chrome use-after-free in ServiceWorker

CVE-2026-78951 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that executes web pages and applications. A use-after-free vulnerability in the ServiceWorker component allows an attacker to execute arbitrary code outside the browser's security sandbox by tricking users into visiting a malicious webpage, potentially compromising user data and system security.

Technical details

The vulnerability is a use-after-free bug in Chrome's ServiceWorker implementation, a mechanism that allows web pages to cache content and work offline. The flaw allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page; no authentication or user interaction beyond visiting the malicious page is required. The attack vector is network-based and affects Chrome versions prior to 152.0.7977.65. This vulnerability was patched in Chrome 152.0.7977.65/64, released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Public disclosure via Chrome Releases blog
  • 2026-08-25: patched: Chrome 152.0.7977.65 released with fix

References

Related threats