Junglewise Threat Intelligence

CVE-2026-79006: Google Chrome HttpsUpgrades origin policy bypass

CVE-2026-79006 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's HttpsUpgrades feature, which automatically upgrades HTTP connections to HTTPS, contains a protection mechanism failure. This vulnerability allows a remote attacker to bypass the browser's web origin policy using specially crafted network traffic, potentially allowing cross-origin attacks that violate browser security boundaries and could lead to unauthorized access to sensitive data from other websites.

Technical details

CVE-2026-79006 is a protection mechanism failure in the HttpsUpgrades component of Google Chrome. The vulnerability allows a remote attacker to bypass web origin policy via crafted network traffic. The issue affects Chrome versions prior to 152.0.7977.65. Attack requires only network-level access (no authentication or user interaction required), and an attacker can exploit this to violate the same-origin policy, potentially gaining access to data or functionality from different origins. A patch is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats