Executive brief
Google Chrome's Sensor component failed to properly verify user permissions before allowing access to sensitive sensor data. An attacker who has already compromised the browser's rendering engine could exploit this to access device sensor information (such as accelerometer or gyroscope data) without authorization, potentially revealing user location or device motion details.
Technical details
This vulnerability is a missing authorization issue in Chrome's Sensor API implementation. The root cause is insufficient permission checking in the Sensor component when a renderer process requests access to hardware sensors. The attack requires the renderer process to be compromised first (out-of-process compromise), but once achieved, an attacker can craft malicious HTML to bypass the authorization check and obtain sensitive sensor data. The vulnerability was fixed in Chrome 152.0.7977.65 released on August 25, 2026. The Chromium project assigned this a Medium severity rating.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79104 disclosed and patched in Chrome 152.0.7977.65