Junglewise Threat Intelligence

CVE-2026-79084: Google Chrome inadequate encryption in Notifications

CVE-2026-79084 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's notification system on Windows failed to properly encrypt sensitive data, allowing attackers to bypass browser security protections through social engineering. An attacker could craft a malicious webpage that tricks users into granting notification permissions, potentially exposing user data or enabling unauthorized actions on behalf of the user.

Technical details

This vulnerability affects the Notifications component in Google Chrome on Windows prior to version 152.0.7977.65 and involves inadequate encryption strength that fails to properly protect notification data. The flaw allows remote attackers to bypass web origin policy—a critical browser security boundary that isolates content from different websites—via a crafted HTML page combined with social engineering to manipulate users. An attacker can exploit this by convincing a user to interact with a specially crafted webpage that triggers notification prompts, potentially compromising the integrity of the origin policy. The vulnerability was patched in Chrome 152.0.7977.65 or later.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Windows

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats