Junglewise Threat Intelligence

CVE-2026-78990: Google Chrome use after free in Compositing

CVE-2026-78990 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser that renders web pages and executes web applications. A use-after-free vulnerability in the Compositing component could allow an attacker to execute code within Chrome's sandbox by tricking a user into visiting a malicious website, potentially leading to data theft or system compromise.

Technical details

This is a use-after-free vulnerability in Google Chrome's Compositing component, a memory safety issue where freed memory is accessed after deallocation. The vulnerability allows remote code execution within the browser's sandbox via a crafted HTML page, requiring only that a user visit a malicious website (no additional authentication or user interaction beyond normal browsing). While code execution is sandboxed rather than arbitrary system-level access, the impact remains significant as it could enable theft of sensitive data within the browser context. The vulnerability was patched in Chrome 152.0.7977.65, released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published via Chrome Releases blog and NVD
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats