Junglewise Threat Intelligence

CVE-2026-79129: Google Chrome use after free in Sessions on Android

CVE-2026-79129 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is vulnerable to a use-after-free bug in its Sessions component that allows a remote attacker to execute arbitrary code outside the browser's sandbox. An attacker can exploit this vulnerability through social engineering and user interaction, potentially giving them full control over the device and access to all user data.

Technical details

A use-after-free vulnerability exists in the Sessions component of Google Chrome on Android prior to version 152.0.7977.65. The vulnerability can be triggered via UI interaction after social engineering, allowing a remote attacker to execute arbitrary code with privileges outside the browser sandbox. The attack requires user interaction and social engineering but does not require authentication. The fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats