PatchSiren cyber security CVE debrief
CVE-2026-79064 Google CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:18:02.030Z and has not been modified since then. This use-after-free vulnerability in Google Chrome's Network component on Mac systems, prior to version 152.0.7977.65, allows remote attackers to execute arbitrary code outside the sandbox via social engineering and a crafted Chrome extension. The vulnerability has a CVSS score of 9.6, indicating critical severity. Administrators should prioritize patching due to the potential for significant impact. Evidence from official CVE Program record and NIST NVD detail page supports the existence of this vulnerability. However, detailed information about affected systems and comprehensive impact analysis is limited. Defenders should verify Chrome installations on Mac systems, review extension usage, and monitor for suspicious activity.
- Vendor
- Product
- Chrome
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of Google Chrome on Mac systems, IT teams responsible for browser management, security professionals monitoring for potential threats, and operators of Chrome-based services should be aware of this vulnerability. They should assess their exposure, apply patches, and implement compensating controls where necessary. Vulnerability management and security teams should prioritize this issue due to its critical severity and potential for exploitation.
Technical summary
A use-after-free vulnerability exists in the Network component of Google Chrome on Mac systems prior to version 152.0.7977.65. This vulnerability allows a remote attacker, through social engineering, to execute arbitrary code outside the sandbox via a crafted Chrome extension. The vulnerability has been assigned a CVSS score of 9.6, indicating critical severity. It is crucial for administrators to prioritize patching due to the potential for significant impact.
Defensive priority
Medium severity vulnerability in Google Chrome, requiring immediate attention due to potential for arbitrary code execution.
Recommended defensive actions
- Apply the official patch to upgrade Google Chrome to version 152.0.7977.65 or later.
- Restrict installation of unverified Chrome extensions.
- Monitor for suspicious activity and implement compensating controls.
- Perform thorough inventory checks for Chrome installations on Mac systems.
- Review Chrome extension permissions and usage.
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page supports the existence of a use-after-free vulnerability in Google Chrome. However, detailed information about affected systems and comprehensive impact analysis is limited. Defenders should verify Chrome installations on Mac systems, review extension usage, and monitor for suspicious activity. The CVE record was published on 2026-08-25T21:18:02.030Z and has not been modified since then. Limited evidence suggests that this vulnerability could be exploited through social engineering tactics.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79064 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79064
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79064 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79064
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/522550059
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.