Executive brief
Google Chrome is a web browser used by billions of users worldwide. A type confusion vulnerability in the Animation component allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting a crafted webpage, potentially compromising user data and system security.
Technical details
This is a type confusion vulnerability in Chrome's Animation component that allows remote code execution within the browser sandbox. The vulnerability affects Chrome versions prior to 152.0.7977.65 and is triggered when a user visits a specially crafted HTML page. Type confusion occurs when the Animation code mishandles object types, allowing an attacker to manipulate memory and achieve code execution. The attack requires user interaction (visiting a malicious webpage) but no authentication. The vulnerability was patched in Chrome 152.0.7977.65, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65