CVE-2026-79197

8.8

Google · Chrome

A use after free vulnerability exists in the V8 engine of Google Chrome, which could allow a remote attacker to execute arbitrary code.

Executive summary

A high severity use after free vulnerability in the Google Chrome V8 engine poses a significant risk of arbitrary code execution for unauthenticated remote attackers.

Vulnerability

This is a use after free vulnerability located within the V8 JavaScript engine. An attacker can trigger this condition through a specially crafted web page, requiring user interaction to execute code in the context of the current user.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution on the host machine. Given the CVSS score of 8.8, this flaw represents a high risk to organizational security, potentially leading to a full system compromise, data exfiltration, or the installation of malicious software.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later to apply the necessary security patches.

Proactive Monitoring: Monitor endpoint activity for unusual browser behavior or unexpected process execution originating from the Chrome application.

Compensating Controls: Ensure that browser security settings are configured to block suspicious scripts and maintain updated antivirus or endpoint detection and response (EDR) solutions.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate action. Administrators must prioritize updating all instances of Google Chrome to the latest stable version to prevent potential exploitation.

More Google CVEs