Executive brief
Google Chrome's Safebrowsing feature helps protect users from malicious websites and downloads. A flaw in how it validates user input allows attackers to bypass these protections by crafting a specially designed file, potentially exposing users to dangerous content and malware.
Technical details
This vulnerability is an improper input validation flaw in the Safebrowsing component of Google Chrome. A remote attacker can exploit it by sending a crafted file that is not properly validated by the Safebrowsing module, allowing the attacker to bypass the system's access restrictions. The attack requires the user to interact with a malicious file but does not require prior authentication. The vulnerability was addressed in Chrome 152.0.7977.65 and later versions. This is a Medium severity issue with a CVSS score of 4.3.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79151 disclosed in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows and Mac, 152.0.7977.64 for Linux