Executive brief
WebProtect is a security feature in Google Chrome that helps protect users from malicious content and phishing attacks. An authorization flaw in WebProtect before version 152.0.7977.65 allows attackers to bypass this protection via a crafted HTML page, potentially exposing users' sensitive information. Users need to update to the latest Chrome version to close this security gap.
Technical details
This vulnerability is an incorrect authorization flaw in the WebProtect component of Google Chrome. An attacker can craft a malicious HTML page that exploits insufficient authorization checks in WebProtect, allowing unauthorized access to sensitive information. The attack requires user interaction (visiting a crafted page) but is network-reachable and does not require authentication. The vulnerability affects all versions of Chrome prior to 152.0.7977.65 (152.0.7977.64 on Linux). Google has patched the issue in Chrome 152.0.7977.65, which was released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79038 disclosed in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)