Junglewise Threat Intelligence

CVE-2026-79090: Google Chrome improper privilege management in Actor

CVE-2026-79090 · Severity: critical · CVSS 9.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser used by billions of users worldwide to access online services and content. A vulnerability in Chrome's Actor component allows an attacker to bypass system access restrictions by tricking users into visiting a malicious webpage, potentially leading to unauthorized access to restricted functionality or data on affected systems.

Technical details

This vulnerability involves improper privilege management in the Actor component of Google Chrome prior to version 152.0.7977.65. The vulnerability can be exploited by a remote attacker through social engineering tactics that convince a user to visit a crafted HTML page. The attack requires user interaction (visiting the malicious page) but does not require authentication. Successful exploitation allows an attacker to bypass system access restrictions. The issue has been patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats