Executive brief
Google Chrome's Federated Credential Management (FedCM) feature contains a memory safety bug that allows attackers to execute arbitrary code outside the browser's sandbox. An attacker can exploit this vulnerability by hosting a crafted webpage and convincing a user to visit it, potentially gaining full control over the victim's system. This bypasses Chrome's security protections and could lead to complete compromise of user data and system resources.
Technical details
This is a use-after-free vulnerability in the FedCM (Federated Credential Management) component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows arbitrary code execution outside the browser sandbox via a crafted HTML page, requiring social engineering (user interaction) as the attack vector. An attacker can escape Chrome's sandbox confinement by exploiting this memory safety issue, achieving full code execution on the victim's machine. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79078 disclosed and Chrome 152 released with fix
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 and later