Description
Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A use-after-free flaw in Chrome's Network code on macOS lets a remote attacker, usually via a socially engineered malicious extension, run arbitrary code outside the sandbox. This can compromise confidentiality, integrity, and availability of the system, because the attacker gains code execution rights in the browser environment.

Affected Systems

Google Chrome browsers on macOS that are earlier than version 152.0.7977.65 are affected. The flaw existed in all releases prior to 152.0.7977.65, so any Mac user running those versions is at risk.

Risk and Exploitability

The crash is triggered by a crafted extension, so the attack requires the user to install or enable that extension—an element of social engineering. The EPSS score is < 1%, indicating a very low probability of public exploitation. The vulnerability is not in CISA's KEV catalog. Nevertheless, it remains a remote code‑execution flaw, and if a malicious extension is installed the attacker can run code with browser process permissions, leading to full system compromise. The CVSS score is 9.6, indicating a very high severity.

Generated by OpenCVE AI on August 26, 2026 at 18:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later
  • Review and remove any unfamiliar or suspicious extensions, and be wary of extensions that request excessive permissions
  • For environments that cannot update immediately, consider disabling extension installation through group policy or Chrome Enterprise policy to block malicious extensions

Generated by OpenCVE AI on August 26, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 26 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Network Code Allowing Arbitrary Code Execution via Malicious Extension

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Network Code Allowing Arbitrary Code Execution via Malicious Extension

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:56:47.974Z

Reserved: 2026-08-25T06:08:27.054Z

Link: CVE-2026-79064

cve-icon Vulnrichment

Updated: 2026-08-26T14:11:54.440Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:02.030

Modified: 2026-08-27T04:17:18.430

Link: CVE-2026-79064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T18:30:02Z

Weaknesses