Junglewise Threat Intelligence

CVE-2026-79066: Google Chrome improper input validation in Navigation

CVE-2026-79066 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an improper input validation flaw in its Navigation component that allows an attacker who has already compromised the browser's renderer process to bypass site isolation protections. Site isolation is a critical security feature that prevents malicious websites from accessing data from other sites. This vulnerability could allow an attacker to access sensitive user data from other origins after gaining initial renderer access through another exploit.

Technical details

This vulnerability is an improper input validation flaw in the Navigation component of Google Chrome. The vulnerability allows a remote attacker who has compromised the renderer process to bypass site isolation protections via a crafted HTML page. Site isolation is a sandbox mechanism that isolates sites from each other to prevent cross-site data theft. The attack requires that the renderer process has already been compromised through another attack vector. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 and later

References

Related threats