Junglewise Threat Intelligence

CVE-2026-79013: Google Chrome improper input validation in Sync

CVE-2026-79013 · Severity: medium · CVSS 5.9 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Sync feature, which synchronizes user data across devices, contains an input validation flaw that allows remote attackers to extract sensitive information without direct user action. An attacker can craft malicious network traffic to exploit this weakness and access synced data such as passwords, browsing history, or other personal information.

Technical details

This vulnerability is an improper input validation flaw in the Sync component of Google Chrome. The vulnerability can be exploited by sending crafted network traffic to a Chrome client with Sync enabled, without requiring user interaction or authentication beyond the normal Sync setup. The attack vector is network-based, allowing remote exploitation. A successful exploit enables an attacker to obtain sensitive information that would normally be protected by Chrome's Sync mechanisms. The vulnerability was patched in Chrome version 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats