ZeroHour

CVE-2026-79150

mass

Use-after-free in Google Chrome Views on Mac enables code execution outside sandbox

CVSS 3.1
9.6 critical
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-79150 is a use-after-free (CWE-416) in the Views component of Google Chrome, the framework that renders the browser's UI layer, affecting Chrome on Mac prior to version 152.0.7977.65. A remote attacker can trigger the flaw by convincing a user to visit or interact with a crafted HTML page, which corrupts memory in the Views layer. Successful exploitation yields arbitrary code execution outside the Chrome sandbox, meaning the attacker escapes the browser's strongest containment boundary and gains the privileges of the browser process on the host. Affected users are those running a vulnerable Chrome build on macOS; other platforms are not named in the advisory. As of this analysis there are no known public proofs-of-concept, the flaw is not in CISA KEV, and its EPSS score of 0.5% (39th percentile) indicates a low near-term likelihood of exploitation, with no confirmed in-the-wild attacks reported.

What to do: Mac users should update Chrome to 152.0.7977.65 or later immediately via Settings > About Chrome, or by enterprise policy for managed fleets. Until patched, avoid interacting with untrusted web content in Chrome on macOS, since the flaw requires user interaction with a crafted page but leads to code execution outside the sandbox. System administrators should verify that managed macOS endpoints are running the fixed build; no workarounds are provided beyond upgrading.

Affected
Google Chrome (on macOS/Mac)All versions prior to 152.0.7977.65 on Mac
Estimated exposure
masshundreds of millions of users (Chrome has roughly 3 billion+ users and is the dominant browser on macOS, which accounts for roughly 15-20% of desktop OS usage) — Chrome's global user base is estimated at over three billion, and applying macOS's ~15-20% desktop market share with Chrome's dominant share on Mac yields an order of magnitude in the hundreds of millions of potentially affected users,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.