Junglewise Threat Intelligence

CVE-2026-79031: Google Chrome improper resource exposure in Preload

CVE-2026-79031 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that isolates websites from one another for security. A flaw in the browser's resource preloading mechanism could allow an attacker to bypass this site isolation protection by sending a specially crafted webpage, potentially enabling unauthorized access to data from other websites in the browser.

Technical details

This vulnerability is an improper resource exposure flaw in Chrome's Preload component that allows bypassing site isolation, a core security boundary in Chrome that prevents cross-site data access. The vulnerability requires a remote attacker to craft a malicious HTML page and trick a user into loading it; no authentication is required, and the attack is network-reachable. By exploiting this, an attacker can circumvent site isolation restrictions to access resources from other websites visited in the same browser session. The vulnerability was patched in Chrome version 152.0.7977.65.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats