CVE-2026-79195

8.8

Google · Chrome

A use after free vulnerability in the Scripting engine of Google Chrome allows for potential remote code execution by an unauthenticated attacker.

Executive summary

A high severity use after free vulnerability in Google Chrome, identified as CVE-2026-79195, poses a major risk of arbitrary code execution via the browser scripting engine.

Vulnerability

This is a use after free (CWE-416) vulnerability located within the browser's script execution engine. An unauthenticated attacker can trigger this condition by convincing a user to visit a malicious website, which may result in arbitrary code execution.

Business impact

The CVSS score of 8.8 reflects the high potential impact of this vulnerability. Successful exploitation could lead to full system takeover, unauthorized access to internal applications, and significant data breaches, all of which pose substantial financial and operational risks to the organization.

Remediation

Immediate Action: Update all installations of Google Chrome to version 152.0.7977.65 or later to resolve this vulnerability.

Proactive Monitoring: Monitor for unusual script execution patterns or browser crashes that could indicate attempts to exploit memory vulnerabilities.

Compensating Controls: Implement robust web content filtering to block known malicious domains and minimize the likelihood of users encountering exploit-laden pages.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Immediate patching is required to mitigate the risk associated with this vulnerability. Security teams should ensure that all endpoints are updated to the latest version and verify that automated update mechanisms are functioning correctly across the enterprise.

More Google CVEs