CVE-2026-78944

8.8

Google · Chrome

A use after free vulnerability exists in the DevTools component of Google Chrome, potentially allowing for arbitrary code execution.

Executive summary

A high-severity use after free vulnerability in Google Chrome DevTools could allow an unauthenticated attacker to execute arbitrary code via a specially crafted web page.

Vulnerability

The flaw is a use after free vulnerability (CWE-416) within the DevTools component. An unauthenticated attacker can trigger this condition by enticing a user to visit a malicious site, as the vulnerability requires user interaction (UI:R).

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the affected system. Given the CVSS score of 8.8, this flaw represents a significant risk, as it allows for unauthorized code execution, potential data theft, and the installation of malware on the host machine.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected browser behavior.

Compensating Controls: Ensure that browser security settings are configured to block malicious sites and consider using enterprise policy to disable unnecessary DevTools features if possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability carries a high severity rating and should be addressed as a priority. Administrators must ensure that the latest stable channel updates for Google Chrome are deployed across the fleet immediately to neutralize the risk of exploitation.

More Google CVEs