Junglewise Threat Intelligence

CVE-2026-79003: Google Chrome incorrect authorization in Device

CVE-2026-79003 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that millions of users rely on for internet browsing. A flaw in Chrome's Device component allows attackers to bypass system access restrictions through a crafted HTML page combined with social engineering, potentially allowing unauthorized access to sensitive system features or data without proper user permission verification.

Technical details

This vulnerability is an incorrect authorization flaw in Chrome's Device component affecting versions prior to 152.0.7977.65. The attack vector requires social engineering to trick a user into visiting a crafted HTML page, after which the attacker can bypass existing system access restrictions. No network-only attack is possible; user interaction and a convincing social engineering pretext are required. The vulnerability allows an attacker to gain unauthorized access to device-level functionality that should be protected by authorization checks. A patch is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats