Executive brief
Google Chrome's Bluetooth component contains a use-after-free vulnerability that allows remote attackers to execute arbitrary code outside the browser's security sandbox. An attacker can exploit this flaw by tricking a user into installing a malicious Chrome extension, potentially gaining full system access and compromising sensitive data or system integrity.
Technical details
A use-after-free vulnerability exists in Chrome's Bluetooth implementation (CVE-2026-79219), affecting versions prior to 152.0.7977.65. The vulnerability allows code to reference memory that has already been freed, potentially leading to arbitrary code execution. Exploitation requires social engineering to convince a user to install a malicious Chrome extension that leverages the vulnerability. Once triggered, the flaw enables arbitrary code execution outside the sandbox boundary, bypassing Chrome's primary security isolation mechanism. The vulnerability was patched in Chrome 152.0.7977.65/152.0.7977.64 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79219 disclosed and patched in Chrome 152
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)