Junglewise Threat Intelligence

CVE-2026-79245: Google Chrome use-after-free in UI

CVE-2026-79245 · Severity: high · CVSS 7.7 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser used by billions of people globally to access web content and services. A use-after-free vulnerability in Chrome's UI component could allow a local attacker who has already compromised the renderer process to execute arbitrary code outside the browser's sandbox, potentially gaining full control of the affected system and accessing sensitive user data.

Technical details

This is a use-after-free vulnerability in the UI component of Google Chrome prior to version 152.0.7977.65. The vulnerability requires the renderer process to already be compromised by an attacker, meaning this is a post-sandbox-escape issue that enables privilege escalation or code execution outside the sandbox boundaries. The attack is local and does not require network access. The fix was made available in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats