Junglewise Threat Intelligence

CVE-2026-79021: Google Chrome missing authorization in InterestGroups

CVE-2026-79021 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a missing authorization vulnerability in its InterestGroups feature that allows a remote attacker with control of the renderer process to bypass system access restrictions via a crafted PDF file. This could enable an attacker to access or modify protected browsing features without proper authorization, potentially affecting user privacy and security.

Technical details

The vulnerability is a missing authorization flaw in the InterestGroups component of Google Chrome prior to version 152.0.7977.65. The attack requires an attacker to have already compromised the renderer process, and leverages a crafted PDF file to trigger the authorization bypass. The vulnerability allows bypassing system access restrictions within the renderer context. This is a post-compromise attack that extends renderer privileges through missing authorization checks. The vulnerability was patched in Chrome 152.0.7977.65.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats