CVE-2026-79183

8.8

Google · Chrome

A use after free vulnerability in the Accessibility component of Google Chrome allows remote attackers to execute arbitrary code via social engineering and UI interaction.

Executive summary

Google Chrome versions prior to 152.0.7977.65 are vulnerable to a use after free flaw that could allow a remote attacker to achieve arbitrary code execution via social engineering.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Accessibility component of Chrome. A remote attacker can trigger this condition through social engineering, leading to code execution outside the browser sandbox following specific UI interactions.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code on the victim's machine. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise, data theft, and loss of confidentiality, integrity, and availability for the affected workstation.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor browser-related process logs and endpoint security telemetry for suspicious activity or unexpected child processes spawned by the Chrome browser.

Compensating Controls: While browser-level patches are the primary defense, ensure that standard endpoint protection and browser security policies are enforced to mitigate the impact of malicious code execution.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

The severity of this vulnerability, combined with the potential for arbitrary code execution, necessitates immediate action. Organizations should prioritize patching all Chrome installations to the latest stable release to eliminate this attack vector. Failure to update leaves endpoints susceptible to browser-based compromises originating from malicious or compromised websites.

More Google CVEs

Sources