Description
Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The flaw is a use‑after‑free bug in Google Chrome’s Extensions component. A crafted extension can trigger a freed memory reference that may lead to the execution of arbitrary code outside Chrome’s sandbox. The affected code paths allow the attacker to run malicious instructions with the privileges of the user’s Chrome process, potentially escalating privileges on the underlying system.

Affected Systems

Google Chrome before version 152.0.7977.65 is affected. All desktop platforms running those releases can be compromised, once a malicious extension is installed.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.6, reflecting a high severity rating. Exploitation requires the user to install or update a malicious extension, so social engineering is the primary attack vector. An EPSS score of 0.00278 (≈0.28%) indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog; nevertheless, the lack of protection against this use‑after‑free still represents a significant risk to any installation of Chrome prior to the stated patch.

Generated by OpenCVE AI on August 26, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or newer.
  • Configure enterprise policy to block third‑party extensions and require extensions to be installed only from the Chrome Web Store.
  • Remove or disable any extensions that appear to be from unknown developers before using the browser.

Generated by OpenCVE AI on August 26, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Extensions Enables Arbitrary Code Execution Outside Sandbox

Wed, 26 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 26 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Extensions Enables Arbitrary Code Execution Outside Sandbox

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:49.684Z

Reserved: 2026-08-25T06:07:47.052Z

Link: CVE-2026-79026

cve-icon Vulnrichment

Updated: 2026-08-26T16:10:25.492Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:58.580

Modified: 2026-08-27T04:17:12.547

Link: CVE-2026-79026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:30:11Z

Weaknesses