• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-79266: use-after-free remote code exec in Google Chrome

A remote attacker can execute arbitrary code in Google Chrome by supplying a specially crafted browser extension that triggers a use-after-free in DevTools and relies on social engineering to get a user to install or enable it. CVE-2026-79266 affects Chrome 152.x prior to the fixed build 152.0.7977.65. Exploitation requires user interaction (social engineering) to install or activate the malicious extension; no network-level access or authentication is required beyond convincing the user.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00382
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this Chrome DevTools use-after-free, so update immediately to the fixed build 152.0.7977.65 and remove or block untrusted extensions until you can patch.

What is CVE-2026-79266?

A remote attacker can execute arbitrary code in Google Chrome by supplying a specially crafted browser extension that triggers a use-after-free in DevTools and relies on social engineering to get a user to install or enable it. CVE-2026-79266 affects Chrome 152.x prior to the fixed build 152.0.7977.65. Exploitation requires user interaction (social engineering) to install or activate the malicious extension; no network-level access or authentication is required beyond convincing the user. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.65 – before 152.0.7977.65152.0.7977.65

Is CVE-2026-79266 being exploited?

Public exploit code is available.

How to fix CVE-2026-79266

  1. Update Google Chrome to 152.0.7977.65 or later.
  2. Remove or disable untrusted or unnecessary extensions and block external extension installs via policy.
  3. Notify users to avoid installing or enabling extensions from untrusted sources and to ignore unexpected extension prompts.
  4. Monitor endpoints for unusual extension activity and crashes related to DevTools.

Frequently asked questions

Is CVE-2026-79266 being actively exploited?

Public exploit code is available for CVE-2026-79266, indicating real-world exploit capability.

Which Chrome versions are affected by CVE-2026-79266?

Chrome 152.x builds before 152.0.7977.65 are affected by CVE-2026-79266; the issue is fixed in 152.0.7977.65.

Is there a patch for CVE-2026-79266?

Yes. Google fixed the vulnerability in Chrome build 152.0.7977.65.

Does CVE-2026-79266 require authentication?

No authentication is required, but exploitation depends on social engineering to get a user to install or enable a malicious extension.

References