ZeroHour

CVE-2026-79012

mass

Use-after-free in Google Chrome Safebrowsing on Mac allows sandbox escape

CVSS 3.1
9.6 critical
EPSS
<1%p44
Published
()
Modified
AI analysis

CVE-2026-79012 is a use-after-free (CWE-416) in the Safebrowsing component of Google Chrome on macOS. An attacker must socially engineer a user into opening a crafted HTML page, after which the memory-corruption flaw can be triggered in the browser process. If successfully exploited, the attacker gains arbitrary code execution outside of Chrome's sandbox, meaning code runs with the privileges of the browser rather than being confined to a sandboxed renderer. Only Chrome users on Mac running versions prior to 152.0.7977.65 are affected; Chrome on other platforms is not named in the advisory. Exploitation has not yet been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.5% chance of exploitation within 30 days.

What to do: Update Google Chrome on macOS to version 152.0.7977.65 or later via chrome://settings/help or your software-management tooling, and verify the running version afterward. Because exploitation requires user interaction, treat unsolicited links and unfamiliar web pages with caution until fleet patching is complete, and prioritize patching users who browse untrusted sites.

Affected
google chromeall versions prior to 152.0.7977.65 on macOS (Mac)
Estimated exposure
masshundreds of millions of Mac users (Chrome is installed on a large fraction of the world's macOS devices) — Chrome is the world's dominant desktop browser with a multi-billion-user install base, and macOS is one of its major supported platforms, so the Mac-only affected population plausibly exceeds one million users by orders of magnitude.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.