Threat reportVulnerabilityTL-2026-2156
Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)
Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (TL-2026-2156) is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-08-26. It has no confirmed attribution, affects Google Google Chrome, references 2 CVEs (CVE-2026-78899, CVE-2026-79282), maps to 7 MITRE ATT&CK techniques (T1059.007, T1106, T1203), and is covered by 9 detection rules and 17 indicators of compromise.
- CVSS
- 9.6/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 7MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-2156
- Threat ID
- TL-2026-2156
- Severity
- CRITICAL
- CVSS
- 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 17
How Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free works
Google's Chrome 152 stable channel update (152.0.7977.64/.65 Windows/Mac, 152.0.7977.64 Linux) closes 327 security bugs, 10 rated critical. Two are headline sandbox-escape flaws: CVE-2026-78899, a V8 use-after-free (CVSS 8.8) letting a crafted HTML page run code inside the renderer sandbox, and CVE-2026-79282, a use-after-free in the ANGLE graphics layer (CVSS 9.6) letting the same kind of page run code outside the sandbox on the host OS.
Chrome 152 (152.0.7977.64/.65 on Windows and macOS, 152.0.7977.64 on Linux) shipped on 2026-08-25 as a stable-channel security update fixing 327 vulnerabilities: 10 critical, 61 high, 184 medium, and 72 low per Google's own severity guidelines. Of the 327, 299 were found internally by Google (part of a broader 2026 trend of AI-assisted internal fuzzing/discovery raising Chrome's internal bug-find rate) and 28 were reported externally, earning roughly $38,000 in combined Chrome VRP bounties this cycle. Nine of the ten critical bugs are use-after-free (CWE-416) memory-safety issues; the tenth (CVE-2026-78935, Mobile) is a use of uninitialized variable.
The two flaws called out by name in vendor and press coverage are both use-after-free bugs, but they sit on opposite sides of Chrome's security boundary.
CVE-2026-78899 (CVSS 3.1 8.8, AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, CWE-416) is a use-after-free in V8, Chrome's JavaScript engine, tracked as Chromium issue 540430406. A remote attacker who gets a victim to load a crafted HTML page (i.e., attacker-controlled JavaScript run by V8) can trigger the bug to execute arbitrary code, but that execution is confined to the Chrome renderer sandbox — it does not by itself give the attacker control of the host. NVD scopes the fixed version to "prior to 152.0.7977.65" without a platform qualifier, i.e., Windows/macOS/Linux/Android all share the vulnerable V8 build.
CVE-2026-79282 (CVSS 3.1 9.6, AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, CWE-416) is a use-after-free in ANGLE, the layer that translates WebGL/OpenGL ES calls issued by web content into the native graphics API calls of the underlying platform (Direct3D, Metal, Vulkan, etc.). Because ANGLE code runs with broader privilege than sandboxed script, an attacker who triggers this bug via a crafted HTML page (WebGL/Canvas content processed through ANGLE's native-API translation) can execute code outside the browser sandbox, directly on the underlying operating system — the more dangerous of the two, since it removes Chrome's core anti-exploitation boundary in one step. Notably, NVD's own CVE record text scopes this specifically to "Google Chrome on Android" ("Use after free in ANGLE in Google Chrome on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page"), while Google's Chrome Releases advisory and all independent press coverage describe the same fix landing simultaneously across Windows, macOS, and Linux in the identical 152.0.7977.64/.65 build — ANGLE is a cross-platform component, so this record treats Android as a confirmed-affected platform per the NVD text in addition to desktop. It was reported to Google's Chrome Vulnerability Reward Program by researcher "Goodluck" on 2026-03-27 (Chromium issue 496807874) and earned a $25,000 bounty, the largest paid in this release cycle.
CVE-2026-78899 (V8) was reported by researcher Jihyeon Jeong of Compsec Lab, Seoul National University, who earned a $500 Chrome VRP reward for it, the smallest bounty of the cycle, consistent with the bug's sandbox-contained impact versus ANGLE's full sandbox escape. Cross-checking cybersecuritynews.com's enumerated table of the release's Chrome-internally-rated Critical bugs shows ten items that do NOT include CVE-2026-78899: CVE-2026-79282 (ANGLE, UAF), CVE-2026-79290/CVE-2026-79052/CVE-2026-79200 (Aura, UAF x3), CVE-2026-79054/CVE-2026-79224 (Chromecast, UAF), CVE-2026-79121 (Chromecast, improper input validation), CVE-2026-79150 (Views, UAF), CVE-2026-78935 (Mobile, uninitialized variable), and CVE-2026-79012 (Safe Browsing, UAF), a bug PCWorld and cybersecuritynews.com both confirm as part of the 152 critical set but absent from the Malwarebytes narrative this record was first sourced from. This means CVE-2026-78899's CVSS 8.8 sits at the NIST qualitative-scale boundary between High (7.0-8.9) and Critical (9.0-10.0); Malwarebytes and syndicating outlets describe it as critical in the loose press sense used for both headline bugs, but it is not among the ten bugs Google's own severity classification (per the cybersecuritynews.com table sourced from Google's release notes) rates Critical, while CVE-2026-79282 (CVSS 9.6) unambiguously is. Both bugs were nonetheless fixed through Google's responsible-disclosure/bug-bounty process before public release; neither Google's advisory, the CISA Known Exploited Vulnerabilities (KEV) catalog (checked directly: 1,682 entries as of 2026-08-26, neither CVE present), nor any of the independent security-press coverage reviewed (including PCWorld's explicit statement that Google has not said any of the fixed vulnerabilities are being actively exploited in attacks) indicates in-the-wild exploitation. Because the fix is now public, the underlying memory-corruption primitives in both V8 and ANGLE are exposed to reverse-engineering from the patch diff (patch-gapping/n-day risk: an attacker can diff 152.0.7977.64/.65 against the prior release to recover the vulnerable code paths and build a working exploit) for any endpoint that has not yet applied the update.
MITRE ATT&CK techniques used in TL-2026-2156
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1106 Native API; T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link
Resource Development
T1587.004 Develop Capabilities: Exploits; T1588.006 Obtain Capabilities: Vulnerabilities; T1608.004 Stage Capabilities: Drive-by Target
Affected products and versions in Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free
- Google — Google Chrome
Vulnerable versions: prior to 152.0.7977.65 (Windows, macOS); prior to 152.0.7977.64 (Linux); prior to 152.0.7977.65 (Android, per NVD CVE-2026-79282 scoping)
Fixed in: 152.0.7977.64/.65 (Windows, macOS); 152.0.7977.64 (Linux); 152.0.7977.65 (Android)
Remediation for Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free
Patches
- Chrome 152.0.7977.64/.65 (Windows, macOS)
- Chrome 152.0.7977.64 (Linux)
- Chrome 152 for Android (equivalent release per NVD CVE-2026-79282 scoping)
Immediate actions
- Update Google Chrome to 152.0.7977.64/.65 (Windows/Mac), 152.0.7977.64 (Linux), or the equivalent Android release via chrome://settings/help
- Fully restart the browser after the update so the patched V8 and ANGLE binaries load
- In managed fleets, confirm the enterprise Chrome policy pushes the 152.0.7977.64/.65 stable channel build (and the Android build via managed Play Store) rather than pinning an older version
Workarounds
- None — both CVE-2026-78899 (V8) and CVE-2026-79282 (ANGLE) are triggerable simply by loading a crafted HTML page, so updating is the only mitigation
Longer-term hardening
- Enable Chrome auto-update for all managed and unmanaged endpoints to minimize patch-gap exposure to memory-safety bugs like these
- Monitor the Chrome Releases blog and Chrome VRP advisories for subsequent stable-channel security updates
- Track Chromium-derived browsers (Edge, Brave, Opera, Vivaldi) for their own 152-equivalent releases, since they share the V8 and ANGLE codebases
CVEs associated with Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free
CVE-2026-78899, CVE-2026-79282
Weaknesses (CWE) in Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free
Timeline of Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free
- Researcher "Goodluck" reports the ANGLE use-after-free (later CVE-2026-79282) to Google's Chrome Vulnerability Reward Program (Chromium issue 496807874).
- Google publishes the 'Stable Channel Update for Desktop' post on the Chrome Releases blog announcing the fixes.
- CVE-2026-78899 and CVE-2026-79282 are published in the National Vulnerability Database (21:17 and 21:18 UTC respectively), tracked upstream as Chromium issues 540430406 and 496807874.
- Google releases Chrome 152 stable channel (152.0.7977.64/.65 Windows/Mac, 152.0.7977.64 Linux), fixing 327 security bugs including 10 critical vulnerabilities (9 use-after-free, 1 uninitialized variable), 299 found internally and 28 reported externally.
- Follow-up sourcing (cybersecuritynews.com, PCWorld) attributes CVE-2026-78899 (V8 UAF) to researcher Jihyeon Jeong of Compsec Lab, Seoul National University ($500 VRP reward), and identifies CVE-2026-79012 (Safe Browsing, use-after-free) as the tenth Chrome-rated-Critical bug in the 152 release, a CVE absent from the original Malwarebytes coverage.
- CISA's Known Exploited Vulnerabilities catalog is checked (1,682 total entries) and contains neither CVE-2026-78899 nor CVE-2026-79282, consistent with vendor statements of no observed in-the-wild exploitation.
- SecurityWeek, cybersecuritynews.com, gbhackers.com, PCWorld, Cryptika, Cyberpress, and Security Boulevard independently publish coverage of the Chrome 152 patch set, corroborating the 327-fix/10-critical breakdown and the other nine Chrome-rated-Critical CVEs (Aura x3, Chromecast x3, Views, Mobile, Safe Browsing).
- Malwarebytes Labs publishes 'Update Chrome before you browse again,' highlighting CVE-2026-78899 and CVE-2026-79282 and urging users to update immediately.
- Press coverage confirms Goodluck's $25,000 bounty for CVE-2026-79282 — the largest single reward in the 152 cycle, out of roughly $38,000 paid in total bounties.
Sources cited for Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free
- Update Chrome before you browse again
- Update Chrome before you browse again (syndicated)
- Stable Channel Update for Desktop
- NVD - CVE-2026-78899
- NVD - CVE-2026-79282
- Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities
- Chrome 152 Patches Over 300 Vulnerabilities
- Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
- Chrome just patched 320+ security flaws, and paid $25K for one of them
- Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities (Cryptika)
- Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Bugs (Cyberpress)
- Chromium Issue 496807874 - ANGLE use-after-free (CVE-2026-79282)
- Chromium Issue 540430406 - V8 use-after-free (CVE-2026-78899)
- CISA Known Exploited Vulnerabilities Catalog (checked, not listed)
Detection coverage for TL-2026-2156
As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2156 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.