CVE-2026-79175
Google · Chrome
A type confusion vulnerability in the Accessibility component of Google Chrome on Windows allows remote attackers to achieve sandbox escape and arbitrary code execution via crafted HTML content.
Executive summary
A high severity type confusion vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox, posing a significant risk to system integrity.
Vulnerability
This flaw stems from a type confusion issue within the Accessibility framework of the browser. An unauthenticated remote attacker can exploit this condition by tricking a user into navigating to a malicious web page, leading to code execution that bypasses the browser sandbox.
Business impact
The ability to execute arbitrary code outside of the browser sandbox represents a critical threat to organizational security. Successful exploitation could allow an attacker to gain full control over the user workstation, leading to data theft, malware installation, or lateral movement within the corporate network. With a CVSS score of 8.3, this vulnerability is classified as high severity, and it necessitates immediate patching to prevent potential system compromise.
Remediation
Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning activities originating from the web browser process or attempts to interact with system-level APIs.
Compensating Controls: Ensure that the browser sandbox remains enabled via enterprise policies and utilize endpoint detection and response (EDR) solutions to detect and block malicious renderer process activity.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the capability for arbitrary code execution and sandbox escape, this vulnerability should be treated with high priority. Organizations must ensure that the automatic update mechanism for Google Chrome is functioning correctly across all endpoints. System administrators should verify that all managed devices have successfully applied the update to version 152.0.7977.65 to mitigate the risk of remote exploitation.