Junglewise Threat Intelligence

CVE-2026-79140: Google Chrome use after free in Views on Mac

CVE-2026-79140 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome is a web browser used by billions of people to access websites and web applications. This vulnerability allows a remote attacker to run malicious code outside the browser's security sandbox by simply tricking a user into visiting a crafted webpage, potentially compromising sensitive data and system integrity.

Technical details

This is a use-after-free vulnerability in the Views component of Google Chrome on macOS, affecting versions prior to 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page, bypassing Chrome's primary security boundary. No special authentication or user interaction beyond visiting a malicious webpage is required. The fix is available in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65 on macOS

Timeline

  • 2026-08-25: disclosed: Chrome 152.0.7977.65 released with fix
  • 2026-08-25: advisory

References

Related threats