CVE-2026-79266

8.8

Google · Chrome

A use after free vulnerability in the DevTools component of Google Chrome could allow an attacker to trigger memory corruption through a malicious web page.

Executive summary

A high severity use after free vulnerability in Google Chrome DevTools could allow a remote attacker to execute arbitrary code or crash the browser application.

Vulnerability

This vulnerability involves a use after free condition in the DevTools component. The attack is unauthenticated but requires user interaction, such as navigating to a malicious page.

Business impact

With a CVSS score of 8.8, this vulnerability poses a severe risk to the integrity and security of the browser environment. Exploitation could allow an attacker to bypass security controls and execute arbitrary code, leading to potential data exfiltration or unauthorized system access.

Remediation

Immediate Action: Update all installations of Google Chrome to version 152.0.7977.65 or higher.

Proactive Monitoring: Review enterprise logs for unusual browser activity or frequent unexplained process crashes.

Compensating Controls: Use browser isolation technologies or endpoint security tools to mitigate the impact of potential memory corruption attacks.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Security teams should enforce mandatory updates for all browser assets to ensure protection against this vulnerability. The high severity rating necessitates immediate action to maintain a secure posture and prevent potential system compromises.

More Google CVEs