Executive brief
Google Chrome's Developer Tools (DevTools) contain a control flow vulnerability that allows attackers to execute arbitrary code within the browser sandbox. An attacker can exploit this by tricking a user into visiting a malicious website, potentially compromising the browser process and any data it handles.
Technical details
This vulnerability involves insufficient control flow management in Chrome's DevTools component. An attacker can craft a malicious HTML page that, when visited by a user, exploits this control flow weakness to execute arbitrary code inside the Chrome sandbox via social engineering. The vulnerability affects Chrome versions prior to 152.0.7977.65. The attack requires user interaction (visiting a crafted page) but no authentication. The fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65