CVE-2026-78944
8.8Google · Chrome
A use after free vulnerability exists in the DevTools component of Google Chrome, potentially allowing for arbitrary code execution.
Executive summary
A high-severity use after free vulnerability in Google Chrome DevTools could allow an unauthenticated attacker to execute arbitrary code via a specially crafted web page.
Vulnerability
The flaw is a use after free vulnerability (CWE-416) within the DevTools component. An unauthenticated attacker can trigger this condition by enticing a user to visit a malicious site, as the vulnerability requires user interaction (UI:R).
Business impact
Successful exploitation of this vulnerability could lead to a complete compromise of the affected system. Given the CVSS score of 8.8, this flaw represents a significant risk, as it allows for unauthorized code execution, potential data theft, and the installation of malware on the host machine.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected browser behavior.
Compensating Controls: Ensure that browser security settings are configured to block malicious sites and consider using enterprise policy to disable unnecessary DevTools features if possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability carries a high severity rating and should be addressed as a priority. Administrators must ensure that the latest stable channel updates for Google Chrome are deployed across the fleet immediately to neutralize the risk of exploitation.