Executive brief
Google Chrome's SafeBrowsing component, which helps protect users from malicious websites, contains a use-after-free memory vulnerability. An attacker could exploit this flaw by sending a crafted webpage to trick a user into visiting it, allowing the attacker to execute malicious code outside Chrome's protective sandbox and potentially take full control of the computer.
Technical details
A use-after-free vulnerability exists in Chrome's SafeBrowsing module, where freed memory is incorrectly accessed, leading to memory corruption. The vulnerability is triggered via a crafted HTML page delivered through social engineering (convincing a user to visit a malicious link). Successful exploitation allows an attacker to break out of Chrome's sandbox and achieve remote code execution with full system privileges. The vulnerability affects Chrome versions prior to 152.0.7977.65 on macOS. Google patched the issue in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 on macOS
Timeline
- 2026-08-25: disclosed: CVE-2026-79012 disclosed; Chrome 152.0.7977.65 released with fix
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65