CVE-2026-79244

8.8

Google · Chrome

A use after free vulnerability exists in the Animation component of Google Chrome, which could allow a remote attacker to trigger memory corruption.

Executive summary

A high severity use after free vulnerability in Google Chrome could allow a remote attacker to execute arbitrary code or cause a crash via a specially crafted web page.

Vulnerability

This is a use after free flaw within the Animation component of the browser. It requires a user to interact with malicious content, as the attack vector relies on user interaction (UI:R).

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a significant risk to organizational endpoints. Successful exploitation could lead to full system compromise, data theft, or complete loss of browser availability, severely impacting business operations and data confidentiality.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor browser crash reports and unexpected process terminations that may indicate exploitation attempts.

Compensating Controls: Deploy endpoint protection solutions capable of detecting and blocking malicious browser-based exploitation techniques.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the critical nature of browser security, administrators should prioritize updating all Chrome instances across the environment. Failure to patch may expose workstations to arbitrary code execution by remote, unauthenticated attackers.

More Google CVEs