Junglewise Threat Intelligence

CVE-2026-79047: Google Chrome use after free in Views

CVE-2026-79047 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is the world's most widely used web browser. A use-after-free vulnerability in the Views component allows a remote attacker to execute arbitrary code outside the browser's security sandbox by tricking a user into visiting a malicious webpage. This could give an attacker complete control over the affected system, enabling data theft, malware installation, and further compromise of the user's machine and network.

Technical details

CVE-2026-79047 is a use-after-free vulnerability in the Views component of Google Chrome. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox by leveraging social engineering to convince a user to visit a crafted HTML page. No authentication is required; the attack is triggered by user interaction with a malicious webpage. The vulnerability is resolved in Chrome version 152.0.7977.65 and later. Google classified this as a High severity issue in Chromium security tracking, though it has been reported with a CVSS score of 9.6 and critical severity due to its sandbox escape capability.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats