Executive brief
Chrome is a widely-used web browser that processes web content from the internet. This vulnerability allows an attacker to bypass system access restrictions by sending a crafted HTML page to a user's browser, potentially gaining unauthorized access to protected system resources or data that the browser should have prevented access to.
Technical details
CVE-2026-79099 is a missing authorization vulnerability in the Network component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass system access restrictions through a crafted HTML page delivered over the network. The attack requires user interaction (visiting a malicious page) but no authentication. An attacker can exploit this to circumvent browser security policies and access restricted resources. The vulnerability was patched in Chrome 152.0.7977.65.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65