Junglewise Threat Intelligence

CVE-2026-79091: Google Chrome use-after-free in Bluetooth on Mac

CVE-2026-79091 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome's Bluetooth component on macOS contains a memory vulnerability that can be exploited when a user visits a specially crafted web page. An attacker leveraging social engineering could use this flaw to execute arbitrary code outside the browser's security sandbox, potentially gaining full access to the user's system and data.

Technical details

This is a use-after-free vulnerability in the Bluetooth component of Google Chrome running on macOS. The vulnerability allows remote code execution (RCE) outside the sandbox via a crafted HTML page when a user is socially engineered to visit a malicious site. The attack vector is network-based and requires user interaction (visiting the malicious page). The vulnerability was patched in Chrome 152.0.7977.65 on macOS and 152.0.7977.64 on Linux, released on August 25, 2026. Despite a reported CVSS score of 9.6, Google's internal assessment classified it as Medium severity in Chromium's security model.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Mac, prior to 152.0.7977.64 on Linux

Timeline

  • 2026-08-25: disclosed: Chrome 152 released with patch for CVE-2026-79091

References

Related threats