Junglewise Threat Intelligence

CVE-2026-79070: Google Chrome incorrect reference resolution in Cache

CVE-2026-79070 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's web cache component contains a flaw that allows remote attackers to bypass web origin policy restrictions. An attacker could craft a malicious HTML page that, when loaded in a vulnerable version of Chrome, exploits this vulnerability to access resources or data from different web origins, potentially leading to unauthorized data exposure or session hijacking.

Technical details

This vulnerability is a web origin policy bypass in Chrome's Cache component caused by incorrect reference resolution. The flaw can be exploited by a remote attacker through a crafted HTML page that triggers the vulnerable code path. No authentication or elevated privileges are required; the attack is triggered by a user visiting a malicious website. An attacker can bypass the same-origin policy, potentially allowing access to sensitive data from other origins. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats