Executive brief
Google Chrome's Sync feature, which synchronizes user data across devices, contains an improper input validation flaw that allows attackers to extract sensitive information through crafted network traffic. This vulnerability could expose user passwords, bookmarks, browsing history, and other synchronized data without requiring user interaction or credentials.
Technical details
The vulnerability is an improper input validation flaw in Chrome's Sync component (CVE-2026-79076). The attack vector is network-based and requires no user authentication or interaction—an attacker can craft malicious network traffic to bypass input validation checks. The vulnerability allows remote attackers to obtain sensitive information from the Sync system. The fix is available in Chrome version 152.0.7977.65 and later, with automatic updates rolling out across Windows, Mac, and Linux platforms.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 released