Junglewise Threat Intelligence

CVE-2026-79067: Google Chrome missing authorization in Network

CVE-2026-79067 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Network component contains a missing authorization flaw that could be exploited by attackers who have compromised the browser's renderer process. An attacker could use a crafted HTML page to bypass system access restrictions and gain unauthorized access to protected resources. This vulnerability affects Chrome versions prior to 152.0.7977.65 on Windows, Mac, and Linux platforms.

Technical details

The vulnerability is a missing authorization check in the Network component of Google Chrome. An attacker who has already compromised the renderer process (requiring prior compromise or sandbox escape) can bypass system access restrictions by crafting a malicious HTML page. The attack requires the renderer process to be compromised beforehand, limiting the immediate attack surface. The flaw was patched in Chrome 152.0.7977.65 and later versions. The Chromium project classified this as a Medium severity issue with a CVSS score of 4.3.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published in Chrome 152 stable channel release notes
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats