CVE-2026-79195: High Use after free in Script
Chromium: CVE-2026-79195 Use after free in Script
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Script in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade
Chromium / Google Chrometo a version that resolves this vulnerability.Fixed in 152.0.7977.65 - Compensating control
Mitigate exploitation by using a crafted HTML page delivery approach resistant browsing controls until Chrome is updated (e.g., restrict/monitor access to untrusted content sources).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome versions are affected?
Google Chrome versions before 152.0.7977.65 are affected. Updating to 152.0.7977.65 or later addresses the affected version range described.
What does exploitation require?
A remote attacker needs to cause the target to process a crafted HTML page. Successful exploitation can result in arbitrary code execution inside the Chrome sandbox.