Executive brief
Google Chrome's QUIC protocol implementation contains an information leak vulnerability that allows remote attackers to extract sensitive information by delivering a specially crafted HTML page. Users who visit a malicious website could have private data exposed without requiring any user interaction beyond normal browsing. The vulnerability affects Chrome versions prior to 152.0.7977.65 across Windows, Mac, and Linux platforms.
Technical details
This is an information disclosure vulnerability in Chrome's QUIC (Quick UDP Internet Connections) protocol implementation. The vulnerability allows a remote attacker to leak sensitive information through a crafted HTML page, requiring only that a user visit a malicious website—no authentication or special user interaction is needed beyond normal web browsing. The attack vector is network-based and the vulnerability was patched in Chrome 152.0.7977.65 and later. The Chromium project assessed this as Medium severity, consistent with the CVSS 6.5 score.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-78893 disclosed with Chrome 152.0.7977.65 stable release
- 2026-08-25: patched: Patched in Chrome 152.0.7977.65