Junglewise Threat Intelligence

CVE-2026-79064: Google Chrome use-after-free in Network on Mac

CVE-2026-79064 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome is a web browser used by hundreds of millions of users to access the internet. A use-after-free vulnerability in the Network component allows an attacker to execute malicious code outside the browser's security sandbox through a specially crafted extension and social engineering, potentially compromising user data, credentials, and system access.

Technical details

A use-after-free vulnerability exists in the Network component of Google Chrome on macOS. The vulnerability can be exploited by a remote attacker via a crafted Chrome extension that leverages social engineering to trick users into installation. Successful exploitation allows arbitrary code execution outside the Chrome sandbox, bypassing the browser's security boundaries. The vulnerability was fixed in Chrome 152.0.7977.65 for Mac. The root cause is improper memory management in the Network processing logic, allowing an attacker to reference freed memory. User interaction (social engineering + extension installation) is required.

Affected products

  • Google Chrome prior to 152.0.7977.65 on macOS

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Mac

References

Related threats