Executive brief
Google Chrome contains a use-after-free vulnerability in the browser's core rendering engine that could allow an attacker with a compromised renderer process to execute arbitrary code and escape the browser's security sandbox. This means malicious code could potentially break out of Chrome's isolated process and gain access to the user's system.
Technical details
This is a use-after-free memory safety vulnerability in the Browser component of Google Chrome. The vulnerability exists in versions prior to 152.0.7977.75 and requires the attacker to have already compromised the renderer process—typically through a prior exploit or crafted HTML page. An attacker can leverage this flaw to execute arbitrary code outside the browser's sandbox, bypassing Chrome's process isolation security boundary. The vulnerability was assigned Chromium security severity High and has a CVSS score of 8.3; Google has released patched version 152.0.7977.75 and later to address this issue.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fix available in Chrome 152.0.7977.75 and later