Junglewise Threat Intelligence

CVE-2026-79257: Google Chrome use after free in Views

CVE-2026-79257 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Views component contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code outside the browser sandbox by sending a crafted HTML page. This vulnerability compromises the fundamental security boundary of the browser, potentially allowing attackers to gain full access to the user's system, bypass all browser protections, and execute malware directly on the underlying operating system.

Technical details

A use-after-free vulnerability exists in the Views component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows memory that has been freed to be accessed and manipulated by an attacker. An attacker can trigger this defect by crafting a malicious HTML page and tricking a user into visiting it. Because this vulnerability enables code execution outside the sandbox (a key browser security feature), an attacker could potentially gain arbitrary code execution with the privileges of the user running Chrome. The vulnerability was patched in Chrome 152.0.7977.65, released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Patched in Chrome 152.0.7977.65
  • 2026-05-29: advisory: Vulnerability reported to Google

References

Related threats