Executive brief
Google Chrome's form handling component had an authorization flaw that allowed attackers to bypass security controls and access sensitive information. An attacker could craft a malicious HTML page that, when opened by a user, would leak personal data or credentials without proper user consent or authentication. This vulnerability affected millions of Chrome users until the release of version 152.0.7977.65.
Technical details
CVE-2026-79133 is an incorrect authorization vulnerability in Google Chrome's Forms component that allows remote attackers to obtain sensitive information. The vulnerability is triggered by user interaction—a victim must visit a malicious HTML page crafted by an attacker. The root cause is improper authorization checks in form data handling, enabling unauthorized access to or disclosure of form-filled data. No authentication or special privileges are required; the attack succeeds through the network via a crafted webpage. Affected versions are Chrome prior to 152.0.7977.65 on Windows, macOS, and Linux. The fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched