Junglewise Threat Intelligence

CVE-2026-79106: Google Chrome improper input validation in Input

CVE-2026-79106 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that processes user-supplied content from websites. A flaw in Chrome's input handling allowed attackers who had compromised the browser's rendering process to bypass web origin policy restrictions and potentially access data from other websites through a malicious HTML page. This could lead to unauthorized access to sensitive user data across website boundaries.

Technical details

The vulnerability is an improper input validation flaw in Chrome's Input component affecting versions prior to 152.0.7977.65. The attack requires a pre-compromised renderer process (e.g., via a sandbox escape or prior code execution) and social engineering to trick a user into viewing a crafted HTML page. An attacker with control of the renderer process could bypass Same-Origin Policy protections, potentially gaining unauthorized access to data from other origins. The vulnerability has been patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats