CVE-2026-79078: High Use after free in FedCM
Chromium: CVE-2026-79078 Use after free in FedCM
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade
Chromium (FedCM)to a version that resolves this vulnerability.Fixed in 152.0.7977.65 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 152.0.7977.65
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome versions are affected?
Google Chrome versions prior to 152.0.7977.65 are affected.
What must an attacker do to exploit this issue?
The attacker needs to induce a user through social engineering to interact with a crafted HTML page. Successful exploitation can execute arbitrary code outside Chrome's sandbox.
What is the recommended remediation?
Update Google Chrome to version 152.0.7977.65 or later.