Executive brief
Google Chrome's network proxy handling contains a use-after-free vulnerability that allows remote attackers to execute arbitrary code outside the browser sandbox via crafted network traffic. Successful exploitation enables attackers to escape the security sandbox and potentially gain full control over the user's system, compromising data confidentiality and integrity.
Technical details
This is a use-after-free vulnerability in Chrome's Proxy component. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox by sending specially crafted network traffic. The attack vector is network-based with no authentication required. The vulnerability affects Chrome versions prior to 152.0.7977.75, and the fix is available in the patched version released on September 1, 2026.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed: Publicly disclosed in Chrome Security release