Executive brief
Google Chrome is a web browser used by billions of people to access websites and web applications. This vulnerability allows a remote attacker to run malicious code outside the browser's security sandbox by simply tricking a user into visiting a crafted webpage, potentially compromising sensitive data and system integrity.
Technical details
This is a use-after-free vulnerability in the Views component of Google Chrome on macOS, affecting versions prior to 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, bypassing Chrome's primary security boundary. No special authentication or user interaction beyond visiting a malicious webpage is required. The fix is available in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on macOS
Timeline
- 2026-08-25: disclosed: Chrome 152.0.7977.65 released with fix
- 2026-08-25: advisory