CVE-2026-84324
Google · Chrome
A use after free vulnerability in the Proxy component of Google Chrome allows a remote attacker to execute arbitrary code via crafted network traffic.
Executive summary
A critical use after free vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution outside the browser sandbox.
Vulnerability
The flaw is a use after free vulnerability located within the Proxy component of the browser. It allows an unauthenticated remote attacker to trigger memory corruption and execute arbitrary code by sending specially crafted network traffic.
Business impact
Successful exploitation of this vulnerability permits a remote attacker to bypass the browser sandbox and execute code with the privileges of the application. Given the CVSS score of 9.0, this represents a critical risk to organizational data confidentiality, system integrity, and endpoint availability. Attackers could potentially pivot from a compromised browser instance to gain deeper access into the underlying host operating system.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.75 or later immediately to incorporate the necessary memory management fixes.
Proactive Monitoring: Monitor network traffic for anomalous patterns or malformed proxy requests that may indicate an attempt to trigger the use after free condition.
Compensating Controls: Ensure that endpoint protection software is active and updated to detect suspicious child processes or unauthorized code execution attempts originating from the browser process.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a severe risk due to its potential for remote code execution and sandbox bypass. Administrators must prioritize the deployment of the latest Chrome update across all managed endpoints to mitigate the threat of unauthorized code execution. Failure to patch this flaw leaves systems exposed to potential remote compromise via malicious network interactions.