Executive brief
Google Chrome is the world's most widely used web browser. This vulnerability allows an attacker to execute arbitrary code outside the browser's security sandbox via a malicious Chrome extension, potentially compromising system integrity and user data. Exploitation requires social engineering to trick users into installing a crafted extension.
Technical details
A use-after-free vulnerability exists in Chrome's Extensions component, allowing memory to be accessed after it has been freed. The vulnerability is triggered when processing a specially crafted Chrome extension. An attacker must socially engineer a user to install the malicious extension; however, once installed, the use-after-free can be exploited to achieve arbitrary code execution outside the sandbox boundary. The vulnerability was patched in Chrome 152.0.7977.65 and later versions. Attack vector is network-based (delivery of the malicious extension) combined with user interaction (social engineering).
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65