Junglewise Threat Intelligence

CVE-2026-79150: Google Chrome use-after-free in Views

CVE-2026-79150 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome on macOS contains a use-after-free vulnerability in the Views UI component that allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page. This could enable attackers to fully compromise a user's system, including stealing credentials, installing malware, and accessing sensitive files. The vulnerability affects Chrome versions prior to 152.0.7977.65.

Technical details

A use-after-free vulnerability exists in the Views component of Google Chrome on macOS prior to version 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox by crafting and serving a malicious HTML page to a targeted user. Use-after-free occurs when memory is accessed after it has been freed, allowing an attacker to hijack execution flow or corrupt application state. The attack vector is network-based and requires only user interaction (visiting a malicious webpage). The vulnerability was reported by Google on 2026-05-29 and has been patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65 on macOS

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats