Description
Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A use‑after‑free flaw exists in the Bluetooth implementation of Google Chrome prior to version 152.0.7977.65. The vulnerability allows an attacker to craft a malicious Chrome extension that, through social engineering, can execute arbitrary code outside the browser sandbox. The weakness is identified as CWE‑416.

Affected Systems

The vulnerability affects Google Chrome browsers older than 152.0.7977.65. End users running these versions are potentially exposed if they install malicious extensions or are tricked into enabling them.

Risk and Exploitability

Because the flaw requires the attacker to supply a malicious extension, the attack vector is remote but relies on user interaction or social engineering. Exploitation would allow code execution with privileges higher than those of the sandbox. The EPSS score is 0.00278 (less than 1%) and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of active exploitation but a high severity risk due to the remote nature of the flaw. The CVSS score of 8.8 indicates high severity.

Generated by OpenCVE AI on August 26, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later.
  • Remove or disable any third‑party extensions that could be malicious or untrusted.
  • Enable or enforce extension‑install restrictions, ensuring that only extensions from verified developers are allowed.

Generated by OpenCVE AI on August 26, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 26 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Bluetooth Use-After-Free Enables Remote Code Execution via Malicious Chrome Extension

Wed, 26 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Bluetooth Use-After-Free Enables Remote Code Execution via Malicious Chrome Extension

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:45.148Z

Reserved: 2026-08-25T06:11:50.618Z

Link: CVE-2026-79219

cve-icon Vulnrichment

Updated: 2026-08-26T16:07:20.342Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:15.977

Modified: 2026-08-27T04:17:50.873

Link: CVE-2026-79219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:30:11Z

Weaknesses