CVE-2026-79209

8.8

Google · Chrome

A type confusion vulnerability in the Google Chrome Animation component allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical type confusion vulnerability in Google Chrome allows remote attackers to execute arbitrary code on user systems through malicious web content.

Vulnerability

This is a type confusion flaw (CWE-843) located within the Animation component of the browser. The vulnerability is exploitable by an unauthenticated remote attacker who lures a user to a specially crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation allows for arbitrary code execution within the browser sandbox, which could lead to full system compromise, unauthorized data access, or the deployment of malware. Given the ubiquity of Chrome in enterprise environments, this flaw poses a significant threat to internal security posture and operational integrity.

Remediation

Immediate Action: Update all Google Chrome instances to the latest stable version (152.0.7977.65 or later) immediately to incorporate the security fix.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected child process spawning related to the Chrome executable.

Compensating Controls: Deploy endpoint protection platforms capable of identifying and blocking malicious web content and utilize browser security policies to restrict execution of untrusted scripts.

Exploitation status

Public Exploit Available: No confirmed public exploit exists.

Analyst recommendation

The high CVSS score and the potential for arbitrary code execution necessitate immediate patching of all browser installations. Organizations should treat this as a high priority update to ensure that the browser sandbox remains effective against malicious web-based exploitation attempts.

More Google CVEs

Sources