Junglewise Threat Intelligence

CVE-2026-79174: Google Chrome incorrect authorization in Extensions

CVE-2026-79174 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's extension authorization system contains a flaw that allows an attacker with access to the browser's rendering process to bypass web origin protections and gain unauthorized access to privileged pages. This could enable an attacker to steal sensitive user data, perform actions on behalf of the user, or compromise the security of installed extensions. The vulnerability requires an initial compromise of the renderer process, but once exploited, can lead to full browser security model breakdown.

Technical details

This vulnerability is an incorrect authorization flaw in Chrome's extension system. An attacker who has compromised the renderer process can bypass web origin policy protections by crafting a malicious HTML page, allowing unauthorized access to privileged extension contexts. The attack requires prior compromise of the renderer process (a separate vulnerability or attack vector) but does not require user interaction beyond the initial renderer compromise. An attacker can exploit this to escape the sandboxed renderer context and access extension APIs and pages that should be isolated. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats