Junglewise Threat Intelligence

CVE-2026-79209: Google Chrome type confusion in Animation

CVE-2026-79209 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users worldwide. A type confusion vulnerability in the Animation component allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting a crafted webpage, potentially compromising user data and system security.

Technical details

This is a type confusion vulnerability in Chrome's Animation component that allows remote code execution within the browser sandbox. The vulnerability affects Chrome versions prior to 152.0.7977.65 and is triggered when a user visits a specially crafted HTML page. Type confusion occurs when the Animation code mishandles object types, allowing an attacker to manipulate memory and achieve code execution. The attack requires user interaction (visiting a malicious webpage) but no authentication. The vulnerability was patched in Chrome 152.0.7977.65, released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats