Junglewise Threat Intelligence

CVE-2026-79056: Google Chrome use-after-free in ServiceWorker

CVE-2026-79056 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ServiceWorker component has a use-after-free vulnerability that allows remote attackers to execute arbitrary code outside the browser's security sandbox. An attacker can exploit this by crafting a malicious HTML page; when visited, the flaw could enable complete compromise of the user's system, including theft of sensitive data or installation of malware.

Technical details

The vulnerability is a use-after-free memory corruption bug in the ServiceWorker component of Google Chrome versions prior to 152.0.7977.65. It is triggered via a crafted HTML page delivered over the network (no user authentication required beyond visiting a webpage). The root cause involves improper memory management where a ServiceWorker object is accessed after being freed, leading to memory corruption. Successful exploitation allows arbitrary code execution outside the browser sandbox, bypassing Chrome's security boundaries. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats