Executive brief
Google Chrome is a web browser used by hundreds of millions of users to access the internet. A use-after-free vulnerability in the Network component allows an attacker to execute malicious code outside the browser's security sandbox through a specially crafted extension and social engineering, potentially compromising user data, credentials, and system access.
Technical details
A use-after-free vulnerability exists in the Network component of Google Chrome on macOS. The vulnerability can be exploited by a remote attacker via a crafted Chrome extension that leverages social engineering to trick users into installation. Successful exploitation allows arbitrary code execution outside the Chrome sandbox, bypassing the browser's security boundaries. The vulnerability was fixed in Chrome 152.0.7977.65 for Mac. The root cause is improper memory management in the Network processing logic, allowing an attacker to reference freed memory. User interaction (social engineering + extension installation) is required.
Affected products
- Google Chrome prior to 152.0.7977.65 on macOS
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Mac