Junglewise Threat Intelligence

CVE-2026-79093: Google Chrome incorrect authorization in Paint

CVE-2026-79093 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Paint component contains an authorization flaw that allows remote attackers to bypass the browser's same-origin policy through a specially crafted webpage. An attacker could exploit this to access or manipulate content from different websites in a single browser session, potentially compromising user data and session security.

Technical details

An incorrect authorization vulnerability in the Paint component of Google Chrome prior to version 152.0.7977.65 allows remote attackers to bypass the web origin policy. The vulnerability is triggered when a user visits a malicious HTML page, enabling an attacker to violate same-origin restrictions. This is a client-side authorization bypass that requires user interaction (visiting a crafted page). The flaw was reported internally by Google on June 12, 2026, and patched in the Chrome 152 stable release on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Fixed in Chrome 152.0.7977.65
  • 2026-08-25: advisory: Published in Chrome Releases blog

References

Related threats