ZeroHour

CVE-2026-84324

mass

Use-After-Free in Google Chrome Proxy Enables Sandbox-Escaping RCE

CVSS 3.1
9.0 critical
EPSS
<1%p22
Published
()
Modified
AI analysis

Google Chrome versions prior to 152.0.7977.75 contain a use-after-free (CWE-416) in the Proxy component of the browser's network stack. A remote attacker can trigger the flaw using crafted network traffic, requiring no user interaction, although the conditions for successful exploitation are complex (CVSS AC:H). If exploited, the bug yields arbitrary code execution outside Chrome's security sandbox, giving the attacker OS-user-level privileges on the victim machine rather than a contained in-browser compromise. All Chrome users on affected builds are in scope, and organizations running Chromium-based browsers that bundle Chrome's network code may also be exposed, though only Chrome is named in the advisory. As of publication the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates just a 0.3% chance of exploitation in the next 30 days, so no exploitation has been observed.

What to do: Update Google Chrome to 152.0.7977.75 or later and verify the running version in chrome://version rather than assuming auto-update has fired, prioritizing internet-reachable browsing hosts and high-value users; there are no known workarounds since the trigger is network traffic. Administrators of Chromium-based browsers should confirm with their vendor whether the underlying Chromium fix has been incorporated into their builds.

Affected
google chromeAll versions prior to 152.0.7977.75
Estimated exposure
mass≈1 billion or more desktop Chrome installations (Chrome holds ~65% desktop browser share and serves 3B+ users overall), shrinking rapidly as auto-update… — Chrome's ~65% desktop browser market share and Google's reported multi-billion user base imply on the order of a billion vulnerable installs existed before the patched release propagated through auto-update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.