CVE-2026-79129
Google · Chrome
A use after free vulnerability in Google Chrome for Android allows remote attackers to execute arbitrary code outside the sandbox through social engineering and UI interaction.
Executive summary
A critical use after free vulnerability in Google Chrome for Android enables remote code execution via social engineering, necessitating an immediate update to version 152.0.7977.65 or later.
Vulnerability
This flaw is a use after free vulnerability, categorized as CWE-416, occurring within the Sessions component. It allows an unauthenticated, remote attacker to achieve arbitrary code execution by tricking a user into specific UI interactions.
Business impact
The potential for remote code execution outside the browser sandbox represents a severe risk to organizational security. Successful exploitation could lead to full device compromise, unauthorized data access, and the potential for lateral movement within a corporate network. Although the Chromium project rated the security severity as medium, the CVSS score of 9.6 highlights the extreme technical impact and the necessity of prioritizing this update.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor mobile device management (MDM) logs for version compliance and review network traffic for unusual patterns originating from mobile browser sessions.
Compensating Controls: While browser-level patches are the primary defense, ensure that mobile security suites are active to detect and block malicious payloads that may be delivered via social engineering vectors.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the CVSS score of 9.6, this vulnerability poses a significant risk to mobile endpoints. Administrators must treat this as a high-priority update to ensure that the browser sandbox remains effective against remote code execution attempts. Ensure that all users update their applications through official channels to mitigate this risk.