Junglewise Threat Intelligence

CVE-2026-78898: Google Chrome incorrect authorization in Downloads

CVE-2026-78898 · Severity: medium · CVSS 5.4 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Downloads feature contained an authorization flaw that allowed attackers to bypass system access restrictions through a crafted web page combined with social engineering. An attacker could trick a user into visiting a malicious website to gain unauthorized access to restricted resources or bypass security controls designed to protect the system.

Technical details

The vulnerability is an incorrect authorization flaw in Google Chrome's Downloads component, classified as Medium severity (Chromium severity). The flaw allows a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. The attack vector is network-based and requires user interaction (visiting a malicious page). The vulnerability was fixed in Chrome version 152.0.7977.65 or later. The root cause stems from insufficient authorization checks in the Downloads functionality, potentially allowing downloaded content or the download process itself to circumvent security boundaries.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats