CVE-2026-79198

8.8

Google · Chrome

A use after free vulnerability exists in the Platform component of Google Chrome, which could allow a remote attacker to execute arbitrary code.

Executive summary

A high severity use after free vulnerability in the Google Chrome Platform component poses a significant risk of arbitrary code execution for unauthenticated remote attackers.

Vulnerability

This is a use after free vulnerability within the browser Platform component. An attacker can leverage this flaw through a malicious website, necessitating user interaction to achieve arbitrary code execution.

Business impact

This vulnerability carries a CVSS score of 8.8, highlighting a high risk to business operations. Exploitation could lead to unauthorized access to sensitive user data, system instability, or full control of the affected workstation by a remote adversary.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later to remediate the affected component.

Proactive Monitoring: Review application logs and endpoint telemetry for anomalous activity that may indicate a memory corruption attempt.

Compensating Controls: Utilize endpoint protection platforms to detect and block malicious payloads that attempt to exploit browser memory vulnerabilities.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The risk of exploitation is high, and organizations should ensure that all Chrome installations are updated immediately. Prompt patching is the only effective way to mitigate this vulnerability.

More Google CVEs