Junglewise Threat Intelligence

CVE-2026-79126: Google Chrome Proxy incorrect functionality information disclosure

CVE-2026-79126 · Severity: medium · CVSS 5.9 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome is a web browser used by hundreds of millions of users worldwide for accessing websites and web applications. A vulnerability in Chrome's Proxy component could allow an attacker on the same local network to intercept and read sensitive information transmitted through crafted network traffic. This could expose user credentials, browsing data, or other confidential information to unauthorized access.

Technical details

This vulnerability in Google Chrome's Proxy component involves incorrect provision of specified functionality, allowing information disclosure through network exposure. An adjacent attacker (on the same network segment) can exploit this flaw by sending crafted network traffic to potentially obtain sensitive information. The vulnerability affects Chrome on Windows versions prior to 152.0.7977.65 and has been patched in Chrome 152.0.7977.65. The attack vector requires adjacent network access and does not require user authentication or interaction. Google assigned this a "Low" security severity rating at the Chromium level, though NVD rated it as medium severity.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 for Windows/Mac released

References

Related threats