Executive brief
Google Chrome's Developer Tools allows developers to debug and inspect web applications. A missing authorization check in DevTools before version 152.0.7977.65 could allow an attacker to trick a user into revealing sensitive information through social engineering. An attacker who persuades a user to interact with a malicious page could gain access to debugging capabilities and sensitive data that should be restricted.
Technical details
This vulnerability is a missing authorization issue in Google Chrome's DevTools component (versions prior to 152.0.7977.65). The vulnerability requires social engineering as part of the attack vector—an attacker cannot exploit it directly but must trick a user into interacting with malicious UI or content. The lack of proper authorization checks allows an attacker to access sensitive information normally restricted to developers. No patch is available beyond upgrading to Chrome 152.0.7977.65 or later. The attack vector is network-based and relies on user interaction.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79154 disclosed in Chrome 152 release notes
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65