Junglewise Threat Intelligence

CVE-2026-79025: Google Chrome improper input validation in Workers

CVE-2026-79025 · Severity: medium · CVSS 4.2 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Web Workers feature failed to properly validate user inputs, allowing an attacker to bypass system access restrictions on Windows, Mac, and Linux systems. An attacker who had already compromised Chrome's renderer process could exploit this via a specially crafted web page to gain unauthorized access to system resources.

Technical details

The vulnerability is an improper input validation flaw in Chrome's Workers component (web workers API). The attack requires the renderer process to be already compromised; the attacker then leverages the input validation weakness to bypass sandbox or system access restrictions via a crafted HTML page. This is a medium-severity sandbox escape affecting Chrome versions prior to 152.0.7977.65. A patch is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats