Junglewise Threat Intelligence

CVE-2026-79197: Google Chrome use-after-free in V8

CVE-2026-79197 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users to access websites and web applications. A use-after-free vulnerability in Chrome's V8 JavaScript engine could allow an attacker to execute malicious code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. This could compromise user data, enable account takeover, or serve as a stepping stone to further attacks on the user's system.

Technical details

A use-after-free vulnerability exists in the V8 JavaScript engine component of Google Chrome versions prior to 152.0.7977.65. The vulnerability can be triggered by a remote attacker through a crafted HTML page, requiring only that a user visit the malicious page (network vector, no authentication required). An attacker can achieve arbitrary code execution within the Chrome sandbox. The vulnerability is patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats