ZeroHour

CVE-2026-84349

mass

Use-after-free sandbox escape in Google Chrome before 152.0.7977.75

CVSS 3.1
8.3 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-84349 is a use-after-free (CWE-416) in the browser process of Google Chrome, fixed in Chrome 152.0.7977.75. It is triggered when a user visits a crafted HTML page, but only after the attacker has already compromised the renderer process, making it effectively a sandbox-escape step in a multi-stage attack. Successful exploitation lets the attacker execute arbitrary code outside Chrome's sandbox at browser-process privilege level on the victim's machine. Anyone running Google Chrome versions prior to 152.0.7977.75 is affected. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and EPSS is low (0.2% probability of exploitation within 30 days), though Chrome memory-corruption bugs of this class are routinely chained in exploit kits once details emerge.

What to do: Update Google Chrome to 152.0.7977.75 or later via chrome://settings/help or through enterprise browser-update policies, and confirm managed fleets have received the new build. Because exploitation requires a pre-existing renderer compromise, keeping all Chromium-based browsers current and enabling Safe Browsing reduces chain risk; watch for PoC publication given this is a High-severity browser-process bug.

Affected
google chromeall versions prior to 152.0.7977.75
Estimated exposure
massbillions of users (Chrome's active install base is on the order of 3+ billion) — Chrome holds roughly 65% of global browser market share, implying billions of active users, and every desktop Chrome installation older than 152.0.7977.75 is within the affected range.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.