Junglewise Threat Intelligence

CVE-2026-79059: Google Chrome information leak in BFCache

CVE-2026-79059 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's back-forward cache (BFCache) feature, which speeds up page navigation by storing page data in memory, contained an information leak vulnerability. An attacker who compromised Chrome's renderer process could exploit this to steal sensitive data from websites across different origins (domains), potentially exposing confidential user information or credentials.

Technical details

This vulnerability is an information disclosure flaw in Chrome's BFCache mechanism. A remote attacker who had already compromised the renderer process could craft a malicious HTML page to extract cross-origin data from cached pages. The attack requires prior compromise of the renderer process and depends on a user visiting a crafted page. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats