Junglewise Threat Intelligence

CVE-2026-79141: Google Chrome incorrect authorization in Browser

CVE-2026-79141 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users to access websites and applications. This vulnerability allows a remote attacker to bypass the browser's web origin policy through a crafted HTML page, potentially enabling unauthorized access to data across different websites or domains.

Technical details

An incorrect authorization vulnerability exists in the Browser component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections via a specially crafted HTML page, without requiring user authentication or special privileges. The vulnerability is network-reachable and exploitable through a malicious webpage. Successful exploitation could enable cross-origin data access or injection attacks. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats