Executive brief
Google Chrome's Bluetooth component on macOS contains a memory vulnerability that can be exploited when a user visits a specially crafted web page. An attacker leveraging social engineering could use this flaw to execute arbitrary code outside the browser's security sandbox, potentially gaining full access to the user's system and data.
Technical details
This is a use-after-free vulnerability in the Bluetooth component of Google Chrome running on macOS. The vulnerability allows remote code execution (RCE) outside the sandbox via a crafted HTML page when a user is socially engineered to visit a malicious site. The attack vector is network-based and requires user interaction (visiting the malicious page). The vulnerability was patched in Chrome 152.0.7977.65 on macOS and 152.0.7977.64 on Linux, released on August 25, 2026. Despite a reported CVSS score of 9.6, Google's internal assessment classified it as Medium severity in Chromium's security model.
Affected products
- Google Chrome prior to 152.0.7977.65 on Mac, prior to 152.0.7977.64 on Linux
Timeline
- 2026-08-25: disclosed: Chrome 152 released with patch for CVE-2026-79091