Description
Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the V8 JavaScript engine within Google Chrome, identified as CWE‑416, allows an attacker to trigger arbitrary code execution inside the browser sandbox through a specially crafted HTML page. The vulnerability is remote; a malicious website can exploit it to run code in the sandboxed environment, potentially compromising user data or surreptitiously initiating further actions without the user’s permission.

Affected Systems

Google Chrome versions earlier than 152.0.7977.65 are affected. The flaw resides in the V8 engine that ships with the stable channel of Chrome. Users on any platform running those versions are vulnerable.

Risk and Exploitability

The vulnerability carries a high severity rating according to Chromium’s assessment. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog, but the nature of the flaw—remote exploitation via a web page—and the prevalence of Chrome browsing make it a significant risk. An attacker would need to lure a user to a malicious HTML page; once the page loads, the use‑after‑free can be triggered to run code within the sandbox, giving the attacker high‑privilege access within the browser context.

Generated by OpenCVE AI on August 25, 2026 at 22:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later, ensuring the latest stable release is installed.
  • Verify that automatic updates are enabled so that Chrome receives security patches in a timely manner.
  • If an update cannot be applied immediately, restrict access to untrusted websites by using a web‑filter or disabling JavaScript for risky sites.

Generated by OpenCVE AI on August 25, 2026 at 22:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title V8 Use‑After‑Free Allows Remote Code Execution in Chrome Via Malicious Web Page

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-25T20:10:09.486Z

Reserved: 2026-08-25T06:03:56.790Z

Link: CVE-2026-78899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:47.290

Modified: 2026-08-25T21:17:47.290

Link: CVE-2026-78899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses