Junglewise Threat Intelligence

CVE-2026-79077: Google Chrome incorrect authorization in WebProtect

CVE-2026-79077 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebProtect component contains an authorization flaw that allows attackers to bypass system access restrictions through a specially crafted webpage. An attacker could exploit this to circumvent security controls intended to prevent unauthorized access to protected resources or system features, potentially compromising the security of users' devices.

Technical details

An incorrect authorization vulnerability exists in the WebProtect component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass system access restrictions by delivering a crafted HTML page to a victim. The vulnerability requires user interaction (visiting a malicious webpage) but does not require authentication. Exploitation permits an attacker to circumvent access controls enforced by WebProtect. The issue was fixed in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats