Junglewise Threat Intelligence

CVE-2026-79235: Google Chrome use after free in WebGL

CVE-2026-79235 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebGL implementation contains a use-after-free memory bug that allows an attacker to execute arbitrary code outside the browser's security sandbox by serving a specially crafted HTML page. This vulnerability could enable attackers to completely compromise a user's system, steal sensitive data, or install malware without the user's knowledge.

Technical details

A use-after-free vulnerability exists in Chrome's WebGL implementation, where memory is accessed after being freed. The vulnerability is triggered by a crafted HTML page served over the network. The attacker requires user interaction (visiting a malicious webpage) but does not need authentication. Successful exploitation allows arbitrary code execution outside the security sandbox, bypassing Chrome's process isolation protections and potentially achieving full system compromise. The vulnerability was fixed in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Chrome 152 stable release published with fix
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats