CVE-2026-84349
massUse-after-free sandbox escape in Google Chrome before 152.0.7977.75
CVE-2026-84349 is a use-after-free (CWE-416) in the browser process of Google Chrome, fixed in Chrome 152.0.7977.75. It is triggered when a user visits a crafted HTML page, but only after the attacker has already compromised the renderer process, making it effectively a sandbox-escape step in a multi-stage attack. Successful exploitation lets the attacker execute arbitrary code outside Chrome's sandbox at browser-process privilege level on the victim's machine. Anyone running Google Chrome versions prior to 152.0.7977.75 is affected. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and EPSS is low (0.2% probability of exploitation within 30 days), though Chrome memory-corruption bugs of this class are routinely chained in exploit kits once details emerge.
What to do: Update Google Chrome to 152.0.7977.75 or later via chrome://settings/help or through enterprise browser-update policies, and confirm managed fleets have received the new build. Because exploitation requires a pre-existing renderer compromise, keeping all Chromium-based browsers current and enabling Safe Browsing reduces chain risk; watch for PoC publication given this is a High-severity browser-process bug.
| google chrome | all versions prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.