Junglewise Threat Intelligence

CVE-2026-79074: Google Chrome information leak in Network component

CVE-2026-79074 · Severity: medium · CVSS 5.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Network component contained an information leak vulnerability that could allow an attacker with control over the browser's rendering process to extract sensitive data by serving a specially crafted webpage. This could expose user data or browser internals to attackers who have already compromised the renderer, representing a secondary attack risk in multi-stage exploits.

Technical details

This is an information disclosure vulnerability in Chrome's Network component, assigned CVE-2026-79074 with medium severity (CVSS 5.3). The vulnerability requires an attacker to have already compromised the renderer process and then trick a user into visiting a crafted HTML page to leak sensitive information. The vulnerability was fixed in Chrome 152.0.7977.65 and later versions. As a renderer-process bug with user interaction required (visiting a page), the attack vector is network-based but depends on prior renderer compromise.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Fixed in Chrome 152.0.7977.65 release

References

Related threats