Executive brief
Google Chrome is a web browser used by billions of people worldwide. This vulnerability involves improper validation of network-related input that, when combined with a compromised browser renderer process, allows an attacker to bypass security restrictions on the system. An attacker would need to first compromise the renderer process (the sandboxed component that runs web content) before this vulnerability can be exploited to escape the browser sandbox.
Technical details
CVE-2026-79032 is an improper input validation vulnerability in the Network component of Google Chrome prior to version 152.0.7977.65. The vulnerability requires that the renderer process is already compromised, making this a post-sandbox-escape vector. An attacker who has achieved code execution in the renderer process can craft a malicious HTML page to bypass system access restrictions through inadequate validation of network input. The vulnerability is patched in Chrome 152.0.7977.65 and later versions. This affects Windows, Mac, and Linux platforms.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65