Executive brief
Google Chrome is the world's most widely used web browser. A use-after-free vulnerability in the Views component allows a remote attacker to execute arbitrary code outside the browser's security sandbox by tricking a user into visiting a malicious webpage. This could give an attacker complete control over the affected system, enabling data theft, malware installation, and further compromise of the user's machine and network.
Technical details
CVE-2026-79047 is a use-after-free vulnerability in the Views component of Google Chrome. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox by leveraging social engineering to convince a user to visit a crafted HTML page. No authentication is required; the attack is triggered by user interaction with a malicious webpage. The vulnerability is resolved in Chrome version 152.0.7977.65 and later. Google classified this as a High severity issue in Chromium security tracking, though it has been reported with a CVSS score of 9.6 and critical severity due to its sandbox escape capability.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65