Executive brief
Google Chrome's accessibility feature contains a use-after-free memory vulnerability that can be exploited by attackers using social engineering tactics to trick users into visiting malicious content. A successful exploit allows an attacker to execute arbitrary code outside the browser's security sandbox, bypassing Chrome's protections and potentially compromising the entire system. This vulnerability affects millions of Chrome users on Windows, Mac, and Linux until they upgrade to version 152.0.7977.65 or later.
Technical details
The vulnerability is a use-after-free condition in Chrome's Accessibility component. The attack requires social engineering to trick a user into interacting with malicious UI content, and leverages improper memory management where freed memory is accessed after deallocation. The vulnerability allows arbitrary code execution outside the sandbox context, giving attackers elevated privileges and system-level access. The vulnerability was reported to Google on June 9, 2026, and patched in Chrome 152.0.7977.65 released on August 25, 2026. This is classified as a High severity issue in Chrome's security framework.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-06-09: disclosed: Vulnerability reported to Google
- 2026-08-25: patched: Chrome 152.0.7977.65 released with fix