CVE-2026-79150
massUse-after-free in Google Chrome Views on Mac enables code execution outside sandbox
CVE-2026-79150 is a use-after-free (CWE-416) in the Views component of Google Chrome, the framework that renders the browser's UI layer, affecting Chrome on Mac prior to version 152.0.7977.65. A remote attacker can trigger the flaw by convincing a user to visit or interact with a crafted HTML page, which corrupts memory in the Views layer. Successful exploitation yields arbitrary code execution outside the Chrome sandbox, meaning the attacker escapes the browser's strongest containment boundary and gains the privileges of the browser process on the host. Affected users are those running a vulnerable Chrome build on macOS; other platforms are not named in the advisory. As of this analysis there are no known public proofs-of-concept, the flaw is not in CISA KEV, and its EPSS score of 0.5% (39th percentile) indicates a low near-term likelihood of exploitation, with no confirmed in-the-wild attacks reported.
What to do: Mac users should update Chrome to 152.0.7977.65 or later immediately via Settings > About Chrome, or by enterprise policy for managed fleets. Until patched, avoid interacting with untrusted web content in Chrome on macOS, since the flaw requires user interaction with a crafted page but leads to code execution outside the sandbox. System administrators should verify that managed macOS endpoints are running the fixed build; no workarounds are provided beyond upgrading.
| Google Chrome (on macOS/Mac) | All versions prior to 152.0.7977.65 on Mac |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.