Junglewise Threat Intelligence

CVE-2026-79244: Google Chrome use-after-free in Animation

CVE-2026-79244 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

A use-after-free memory vulnerability in Google Chrome's Animation component allows an attacker to execute arbitrary code within the browser's sandboxed process by serving a malicious HTML page. While the vulnerability is restricted to the sandbox environment (limiting direct system access), successful exploitation could allow an attacker to compromise the browsing process and potentially access sensitive user data or credentials.

Technical details

This is a use-after-free vulnerability in the Animation component of Google Chrome versions prior to 152.0.7977.65. The vulnerability results from improper memory management where a freed object is accessed, potentially leading to memory corruption. Attack requires user interaction (visiting a crafted HTML page) and is delivered via network, making it remotely exploitable. An attacker can achieve arbitrary code execution within the Chrome sandbox by serving malicious HTML content. The vulnerability is patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed

References

Related threats