Description
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Chrome proxy component allowed a remote attacker to craft network traffic that could cause Chrome to execute arbitrary code outside its sandbox. The bug exploits a dangling pointer that persists after the proxy object is freed, enabling memory corruption and code execution with system privileges. The consequent impact is the ability to run malicious code on the user’s machine without sandbox restrictions, potentially compromising confidentiality, integrity, and availability of the system.

Affected Systems

The vulnerability affects Google Chrome desktop releases prior to version 152.0.7977.75. Any machine running one of those older Chrome versions is vulnerable when it processes crafted network traffic through the proxy subsystem.

Risk and Exploitability

Chromium classifies this as a high‑severity issue. While an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation remains elevated because the flaw can be triggered remotely via network traffic. The attack vector is inferred to require an attacker to send specially crafted packets to the Chrome proxy, making the threat most relevant to systems exposed to potentially malicious network traffic.

Generated by OpenCVE AI on September 2, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.75 or later to remove the use‑after‑free bug
  • Ensure automatic updates are enabled so that future patches are applied promptly
  • Restrict or monitor proxy traffic if updating is not immediately possible, or apply network filtering to block suspicious packets

Generated by OpenCVE AI on September 2, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use-After-Freed in Chrome Proxy

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:26.522Z

Reserved: 2026-09-01T16:20:10.441Z

Link: CVE-2026-84324

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:27.230

Modified: 2026-09-02T00:18:27.230

Link: CVE-2026-84324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:15:05Z

Weaknesses