Executive brief
Google Chrome's extension system contains an information leak vulnerability that could allow an attacker to obtain cross-origin data through a malicious or compromised extension. While exploitation requires social engineering to trick users into installing a crafted extension, successful exploitation could expose sensitive data from websites users visit. This vulnerability affects Chrome versions prior to 152.0.7977.65.
Technical details
The vulnerability is an information leak in Chrome's Extensions component affecting versions prior to 152.0.7977.65. It allows a remote attacker to obtain cross-origin data via a crafted Chrome extension, requiring social engineering to convince the user to install the malicious extension. The attack vector is network-based and depends on user interaction (extension installation). The vulnerability has been patched in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-78960 disclosed and patched in Chrome 152.0.7977.65
- 2026-08-25: other: Chromium security severity: Medium