Executive brief
Google Chrome is a widely-used web browser that runs code from websites in sandboxed environments to prevent unauthorized access to the underlying system. A use-after-free vulnerability in Chrome's Platform component allowed attackers to execute arbitrary code within this sandbox by tricking users into visiting a malicious website, potentially compromising user data and browser functionality.
Technical details
A use-after-free vulnerability exists in the Platform component of Google Chrome prior to version 152.0.7977.65. This memory safety issue allows remote attackers to achieve arbitrary code execution within the Chrome sandbox via a crafted HTML page. The vulnerability is triggered when a user visits a malicious website without requiring prior authentication or user interaction beyond normal browsing. Although the code execution is restricted to the sandbox environment, it represents a significant attack vector for further exploitation and data exfiltration. The fix is available in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65