DIRAS TAKE
Urgent: public exploit code exists for this Chrome DevTools use-after-free, so update immediately to the fixed build 152.0.7977.65 and remove or block untrusted extensions until you can patch.
What is CVE-2026-79266?
A remote attacker can execute arbitrary code in Google Chrome by supplying a specially crafted browser extension that triggers a use-after-free in DevTools and relies on social engineering to get a user to install or enable it. CVE-2026-79266 affects Chrome 152.x prior to the fixed build 152.0.7977.65. Exploitation requires user interaction (social engineering) to install or activate the malicious extension; no network-level access or authentication is required beyond convincing the user. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.65 – before 152.0.7977.65 | 152.0.7977.65 |
Is CVE-2026-79266 being exploited?
Public exploit code is available.
How to fix CVE-2026-79266
- Update Google Chrome to 152.0.7977.65 or later.
- Remove or disable untrusted or unnecessary extensions and block external extension installs via policy.
- Notify users to avoid installing or enabling extensions from untrusted sources and to ignore unexpected extension prompts.
- Monitor endpoints for unusual extension activity and crashes related to DevTools.
Frequently asked questions
Is CVE-2026-79266 being actively exploited?
Public exploit code is available for CVE-2026-79266, indicating real-world exploit capability.
Which Chrome versions are affected by CVE-2026-79266?
Chrome 152.x builds before 152.0.7977.65 are affected by CVE-2026-79266; the issue is fixed in 152.0.7977.65.
Is there a patch for CVE-2026-79266?
Yes. Google fixed the vulnerability in Chrome build 152.0.7977.65.
Does CVE-2026-79266 require authentication?
No authentication is required, but exploitation depends on social engineering to get a user to install or enable a malicious extension.
References
- nvd.nist.gov/vuln/detail/CVE-2026-79266
- cve.org/CVERecord?id=CVE-2026-79266
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- issues.chromium.org/issues/537145191
- All Google CVEs on CVE Radar
- CVEs published in September 2026