Executive brief
Google Chrome is a widely-used web browser used by millions of users to access the internet. A use-after-free vulnerability in Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser sandbox by tricking users into visiting a malicious webpage. Exploitation could lead to unauthorized data access, credential theft, or further compromise of the user's system.
Technical details
A use-after-free vulnerability exists in the V8 JavaScript engine component of Google Chrome prior to version 152.0.7977.65. The vulnerability is triggered via a crafted HTML page and allows remote code execution within the Chrome sandbox. Attack requires only that a user visits a malicious website; no authentication or additional user interaction is needed beyond normal browsing. An attacker can execute arbitrary code with the privileges of the browser process, potentially escaping the sandbox through secondary exploits. The vulnerability has been patched in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65