CVE-2026-78990
8.8Google · Chrome
A use after free vulnerability exists in the Compositing component of Google Chrome, which may lead to memory corruption or arbitrary code execution.
Executive summary
A high-severity use after free vulnerability in the Google Chrome Compositing engine could allow an unauthenticated attacker to achieve arbitrary code execution via user interaction.
Vulnerability
This is a use after free vulnerability (CWE-416) within the Compositing process. It requires an unauthenticated attacker to influence the user to interact with malicious content, leveraging the browser's rendering process to execute code.
Business impact
The ability for an attacker to execute arbitrary code within the browser context poses a severe risk to organizational assets. With a CVSS score of 8.8, this vulnerability allows attackers to bypass security boundaries, potentially leading to total system compromise or the theft of sensitive user credentials and session tokens.
Remediation
Immediate Action: Apply the latest Google Chrome security updates to reach version 152.0.7977.65 or later.
Proactive Monitoring: Review browser logs for signs of abnormal crashes or unexpected memory spikes that may indicate exploitation attempts.
Compensating Controls: Utilize endpoint protection platforms to detect and block known malicious payloads that typically accompany browser-based exploits.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Prompt remediation is necessary to prevent potential exploitation. Security teams should enforce the immediate application of browser updates to ensure the latest patches are active and the attack surface is minimized.