Executive brief
Google Chrome is a widely-used web browser relied upon by billions of users to access the internet and cloud applications. A flaw in Chrome's WebProtect security feature allows attackers to craft specially designed web pages that bypass authorization checks, enabling them to leak sensitive information from users who visit the malicious page. This could expose personal data, credentials, or other confidential information handled by the browser.
Technical details
An incorrect authorization vulnerability exists in the WebProtect component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass authorization controls and leak sensitive information by serving a crafted HTML page to a victim. The attack requires no user interaction beyond visiting the malicious page and is delivered over the network. Chromium security rated this issue as Medium severity. The fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-78907 disclosed in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65