Description
Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply patch
AI Analysis

Impact

A type confusion bug in the Animation component of Google Chrome allows a crafted HTML page to trigger the browser to run code inside its sandbox. The flaw stems from improper type handling and could let an attacker compromise the confidentiality, integrity, or availability of the system by executing code with the user’s privileges. The impact is a potential escape from the browser sandbox and execution of code.

Affected Systems

Google Chrome builds prior to version 152.0.7977.65 are affected. Any user running an older Chrome that processes a maliciously crafted HTML page is at risk.

Risk and Exploitability

Chromium rates the vulnerability as high severity with a CVSS score of 8.8. The EPSS score is under 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to entice a user to view or download a maliciously crafted HTML page. The exploit therefore depends on user interaction and does not require local privilege escalation, making it an opportunistic, network–level attack.

Generated by OpenCVE AI on August 26, 2026 at 20:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later using the official update channel.
  • Limit the use of extensions that grant extensive page access permissions.
  • Keep the operating system and Chrome patched, enable safe browsing, and use blocklists to reduce the chance of executing malicious content.

Generated by OpenCVE AI on August 26, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Type confusion in Chrome Animation enables potential sandbox escape and code execution

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Type confusion in Chrome Animation enables potential sandbox escape and code execution

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:58:00.905Z

Reserved: 2026-08-25T06:11:36.747Z

Link: CVE-2026-79209

cve-icon Vulnrichment

Updated: 2026-08-26T16:21:59.237Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:14.820

Modified: 2026-08-27T04:17:47.047

Link: CVE-2026-79209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:15:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')