Junglewise Threat Intelligence

CVE-2026-79033: Google Chrome insufficient control flow management in DevTools

CVE-2026-79033 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Developer Tools (DevTools) contain a control flow vulnerability that allows attackers to execute arbitrary code within the browser sandbox. An attacker can exploit this by tricking a user into visiting a malicious website, potentially compromising the browser process and any data it handles.

Technical details

This vulnerability involves insufficient control flow management in Chrome's DevTools component. An attacker can craft a malicious HTML page that, when visited by a user, exploits this control flow weakness to execute arbitrary code inside the Chrome sandbox via social engineering. The vulnerability affects Chrome versions prior to 152.0.7977.65. The attack requires user interaction (visiting a crafted page) but no authentication. The fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats