Description
Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A vulnerability in the Animation component of Google Chrome allowed a remote attacker to leak application data by loading a specially crafted HTML page. The weakness is a classic information‑leak flaw (CWE‑200) and enables the attacker to read data that should remain private to the browser process.

Affected Systems

Google Chrome is affected. Versions prior to 152.0.7977.65 are vulnerable, while all later releases contain the fix. The issue does not affect non‑Chrome browsers or other Google products.

Risk and Exploitability

The vulnerability can be triggered by visiting a malicious web page, so the likely attack vector is remote and web‑based as inferred from the description. No publicly available exploits are reported, and the CVE is not listed in the CISA KEV catalog. The CVSS score of 6.5 places it in the medium severity range, and with an EPSS score of less than 1%, the likelihood of exploitation remains low, but the potential for sensitive data exposure warrants patching.

Generated by OpenCVE AI on August 26, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 152.0.7977.65 or newer to remove the flaw.
  • If an upgrade cannot be performed immediately, restrict or disable CSS animations via enterprise policy to remove the attack surface.
  • Deploy the patch across all devices using the central management console.

Generated by OpenCVE AI on August 26, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chromium Animation Component Information Leak Allows Remote Web Pages to Extract Sensitive Data

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chromium Animation Component Information Leak Allows Remote Web Pages to Extract Sensitive Data

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:40:31.941Z

Reserved: 2026-08-25T06:13:24.781Z

Link: CVE-2026-79293

cve-icon Vulnrichment

Updated: 2026-08-26T18:15:17.988Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:23.530

Modified: 2026-08-27T17:49:28.317

Link: CVE-2026-79293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:30:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor