Junglewise Threat Intelligence

CVE-2026-79026: Google Chrome use after free in Extensions

CVE-2026-79026 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is the world's most widely used web browser. This vulnerability allows an attacker to execute arbitrary code outside the browser's security sandbox via a malicious Chrome extension, potentially compromising system integrity and user data. Exploitation requires social engineering to trick users into installing a crafted extension.

Technical details

A use-after-free vulnerability exists in Chrome's Extensions component, allowing memory to be accessed after it has been freed. The vulnerability is triggered when processing a specially crafted Chrome extension. An attacker must socially engineer a user to install the malicious extension; however, once installed, the use-after-free can be exploited to achieve arbitrary code execution outside the sandbox boundary. The vulnerability was patched in Chrome 152.0.7977.65 and later versions. Attack vector is network-based (delivery of the malicious extension) combined with user interaction (social engineering).

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats