Executive brief
Google Chrome's accessibility component contains a type confusion vulnerability that allows an attacker who has already compromised the renderer process to execute arbitrary code outside the security sandbox. This could enable an attacker to gain full control of the browser and access sensitive user data, bypass security protections, and perform unauthorized actions on behalf of the user.
Technical details
CVE-2026-79175 is a type confusion vulnerability in Chrome's Accessibility component that allows code execution outside the sandbox. The vulnerability requires the renderer process to already be compromised, meaning an attacker would first need to exploit another vulnerability to break out of the renderer sandbox before leveraging this flaw. The attacker can then craft a malicious HTML page to trigger the type confusion and achieve arbitrary code execution with full browser privileges. The vulnerability affects Chrome on Windows versions prior to 152.0.7977.65 and has been fixed in the stable release. Google assigned this a High security severity rating with a CVSS score of 8.3.
Affected products
- Google Chrome prior to 152.0.7977.65 on Windows
Timeline
- 2026-08-25: disclosed: Chrome 152 stable release with fix published
- 2026-04-02: other: Vulnerability reported to Google