CVE-2026-79183
8.8Google · Chrome
A use after free vulnerability in the Accessibility component of Google Chrome allows remote attackers to execute arbitrary code via social engineering and UI interaction.
Executive summary
Google Chrome versions prior to 152.0.7977.65 are vulnerable to a use after free flaw that could allow a remote attacker to achieve arbitrary code execution via social engineering.
Vulnerability
This is a use after free vulnerability (CWE-416) within the Accessibility component of Chrome. A remote attacker can trigger this condition through social engineering, leading to code execution outside the browser sandbox following specific UI interactions.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code on the victim's machine. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise, data theft, and loss of confidentiality, integrity, and availability for the affected workstation.
Remediation
Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor browser-related process logs and endpoint security telemetry for suspicious activity or unexpected child processes spawned by the Chrome browser.
Compensating Controls: While browser-level patches are the primary defense, ensure that standard endpoint protection and browser security policies are enforced to mitigate the impact of malicious code execution.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
The severity of this vulnerability, combined with the potential for arbitrary code execution, necessitates immediate action. Organizations should prioritize patching all Chrome installations to the latest stable release to eliminate this attack vector. Failure to update leaves endpoints susceptible to browser-based compromises originating from malicious or compromised websites.