Junglewise Threat Intelligence

CVE-2026-79195: Google Chrome use after free in Script

CVE-2026-79195 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by millions worldwide to access websites and web applications. A use-after-free vulnerability in Chrome's Script component allows attackers to execute arbitrary code within the browser sandbox by tricking users into visiting a malicious webpage, potentially leading to data theft, credential harvesting, or further system compromise.

Technical details

A use-after-free vulnerability exists in the Script component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code within the Chrome sandbox via a specially crafted HTML page. No authentication or special user interaction beyond visiting the malicious page is required. Exploitation could allow code execution with the privileges of the browser sandbox, which is designed to restrict access to the underlying system. The vulnerability was reported by Google's internal security team and patched in Chrome 152.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published in Chrome Stable Channel Update
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats