Executive brief
Google Chrome's TabGroups feature contains an authorization flaw that allows a remote attacker to leak sensitive information by sending specially crafted network traffic. This could expose confidential user data without requiring user interaction or special privileges. The vulnerability affects Chrome versions prior to 152.0.7977.65 and is patched in the latest stable release.
Technical details
CVE-2026-79107 is an incorrect authorization vulnerability in the TabGroups feature of Google Chrome. The flaw allows a remote attacker to bypass authorization controls and potentially leak sensitive information through crafted network traffic. No special authentication is required and the attack is network-reachable. The vulnerability has been fixed in Chrome 152.0.7977.65 and later versions released on August 25, 2026. Chromium security team classified this as Medium severity.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65