Executive brief
Google Chrome on macOS contains a use-after-free vulnerability in the Views UI component that allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page. This could enable attackers to fully compromise a user's system, including stealing credentials, installing malware, and accessing sensitive files. The vulnerability affects Chrome versions prior to 152.0.7977.65.
Technical details
A use-after-free vulnerability exists in the Views component of Google Chrome on macOS prior to version 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox by crafting and serving a malicious HTML page to a targeted user. Use-after-free occurs when memory is accessed after it has been freed, allowing an attacker to hijack execution flow or corrupt application state. The attack vector is network-based and requires only user interaction (visiting a malicious webpage). The vulnerability was reported by Google on 2026-05-29 and has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on macOS
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65