Executive brief
Google Chrome's password manager contains a reference resolution bug that could allow a remote attacker to bypass system access controls. An attacker could exploit this by crafting a malicious file, potentially gaining unauthorized access to stored passwords or other sensitive system data without proper authentication.
Technical details
This vulnerability involves incorrect reference resolution in the Passwords component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass system access restrictions through a specially crafted file. The vulnerability requires no user interaction beyond opening a crafted file, making it a network-reachable attack vector. An attacker can exploit this to circumvent security boundaries protecting password storage and other sensitive system resources. The issue is fixed in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79049 disclosed in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65