Junglewise Threat Intelligence

CVE-2026-79034: Google Chrome information leak in CORS

CVE-2026-79034 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that processes web pages and executes scripts from the internet. This vulnerability allows an attacker who gains control of Chrome's rendering process to bypass security policies and leak sensitive data from websites hosted on different domains (cross-origin data). An exploit requires the attacker to first compromise the renderer process, typically through another vulnerability or social engineering.

Technical details

The vulnerability is an information leak in the Cross-Origin Resource Sharing (CORS) implementation in Chrome's renderer process. An attacker who has already compromised the renderer process can craft a malicious HTML page to extract cross-origin data that should normally be restricted by the browser's same-origin policy. The attack vector requires prior renderer compromise and user interaction (loading the crafted HTML page). Google patched this issue in Chrome version 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats