Executive brief
Google Chrome contains a use-after-free memory vulnerability in the TabStrip component that allows attackers to execute arbitrary code outside the browser's sandbox protection. Exploitation requires social engineering to trick a user into interacting with a malicious UI element, potentially leading to complete compromise of the user's system and data.
Technical details
A use-after-free vulnerability exists in the TabStrip component of Google Chrome prior to version 152.0.7977.75. The vulnerability can be triggered through UI interaction combined with social engineering, allowing a remote attacker to escape the sandbox and execute arbitrary code with the privileges of the Chrome process. Exploitation requires user interaction and is not a network-based attack. The vulnerability has been patched in Chrome 152.0.7977.75 and later.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed