Junglewise Threat Intelligence

CVE-2026-79266: Google Chrome use after free in DevTools

CVE-2026-79266 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's developer tools contain a use-after-free memory vulnerability that allows remote attackers to execute arbitrary code within the browser sandbox. An attacker could exploit this by hosting a malicious Chrome extension and using social engineering to trick users into installing it, potentially compromising sensitive data or enabling unauthorized system access.

Technical details

A use-after-free vulnerability exists in Chrome's DevTools component (part of developer tools). The vulnerability is triggered via a crafted Chrome extension that exploits the memory management flaw. Attack vector is network-based, requiring social engineering to convince a user to install a malicious extension. The attacker achieves code execution within the Chrome sandbox. The vulnerability affects Chrome versions prior to 152.0.7977.65 and was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats