Junglewise Threat Intelligence

CVE-2026-78967: Google Chrome missing authorization in BFCache

CVE-2026-78967 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a missing authorization vulnerability in its BFCache (Back/Forward Cache) feature, which is used to store cached pages when navigating browser history. An attacker who compromises the renderer process could bypass system access restrictions by crafting a malicious HTML page, potentially gaining unauthorized access to sensitive data or operations that should be restricted.

Technical details

This vulnerability is a missing authorization flaw in Google Chrome's BFCache component, affecting versions prior to 152.0.7977.65. The vulnerability requires the attacker to have already compromised the renderer process (e.g., through a separate RCE vulnerability), but from that position, they can craft a specially designed HTML page to bypass access restrictions. The flaw allows unauthorized access to functionality or data that should be restricted by the browser's security model. The vulnerability was fixed in Chrome 152.0.7977.65 released on August 25, 2026. Exploitation requires local renderer process compromise and user interaction with a crafted page.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats