Description
Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Animation module of Google Chrome, allowing a remote attacker to execute arbitrary code within the browser’s sandbox by delivering a specially crafted HTML page. Because the flaw occurs during page rendering, an attacker could compromise the sandbox boundaries and potentially escape to the host system, though the attack is constrained to the sandboxed process. The issue is rated low severity by Chromium.

Affected Systems

This flaw affects installations of Google Chrome versions older than 152.0.7977.65, regardless of operating system. Users running the affected version should upgrade to the patched release or newer, which removes the use‑after‑free condition in the Animation component.

Risk and Exploitability

There is no publicly available EPSS score and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.8 indicates a high severity issue. Even though exploitation is confined to the browser sandbox, the high score reflects the risk that an attacker can execute arbitrary code within the sandboxed process by delivering a crafted HTML page. The attack requires the victim to view the malicious page and is most dangerous for users who run web content from untrusted sources.

Generated by OpenCVE AI on August 26, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later to remove the use‑after‑free in the animation module.
  • Configure Chrome to enforce strict sandboxing for all web content and disable local file access where possible.
  • Verify that users avoid opening suspicious HTML files or visiting untrusted websites.

Generated by OpenCVE AI on August 26, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Animation Allows Remote Code Execution

Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Animation Allows Remote Code Execution

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:55:26.642Z

Reserved: 2026-08-25T06:12:28.206Z

Link: CVE-2026-79244

cve-icon Vulnrichment

Updated: 2026-08-26T00:07:01.382Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:18.763

Modified: 2026-08-31T18:14:05.160

Link: CVE-2026-79244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T02:30:04Z

Weaknesses