Executive brief
Google Chrome's Network component contained an information leak vulnerability that could allow an attacker with control over the browser's rendering process to extract sensitive data by serving a specially crafted webpage. This could expose user data or browser internals to attackers who have already compromised the renderer, representing a secondary attack risk in multi-stage exploits.
Technical details
This is an information disclosure vulnerability in Chrome's Network component, assigned CVE-2026-79074 with medium severity (CVSS 5.3). The vulnerability requires an attacker to have already compromised the renderer process and then trick a user into visiting a crafted HTML page to leak sensitive information. The vulnerability was fixed in Chrome 152.0.7977.65 and later versions. As a renderer-process bug with user interaction required (visiting a page), the attack vector is network-based but depends on prior renderer compromise.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Fixed in Chrome 152.0.7977.65 release