Junglewise Threat Intelligence

CVE-2026-78983: Google Chrome use after free in Views

CVE-2026-78983 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of people worldwide. A vulnerability in the Views component allows an attacker who has already compromised Chrome's renderer process to execute malicious code outside the browser's sandbox protection, potentially gaining full control of the user's system.

Technical details

This is a use-after-free vulnerability in the Views component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker who has compromised the renderer process to execute arbitrary code outside the sandbox by delivering a crafted HTML page. Use-after-free bugs occur when memory is accessed after being freed, potentially allowing attackers to overwrite memory and execute code. The attack requires prior compromise of the renderer process, which is typically achieved through a separate vulnerability (e.g., renderer RCE). The vulnerability was patched in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome before 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 and later

References

Related threats