Junglewise Threat Intelligence

CVE-2026-79179: Google Chrome incorrect authorization in DOM

CVE-2026-79179 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of people worldwide to access websites and web applications. A flaw in Chrome's DOM (Document Object Model) handling could allow an attacker to bypass authorization checks and leak sensitive information from web pages. An attacker could exploit this by crafting a malicious HTML page that tricks the browser into exposing data that should be protected.

Technical details

This vulnerability is an incorrect authorization flaw in Chrome's DOM implementation that allows a remote attacker to bypass access controls and leak sensitive information. The vulnerability requires user interaction (opening a crafted HTML page) and is exploitable over the network without requiring authentication. An attacker can craft a specially-designed HTML page that, when visited, causes the browser to expose protected data that should be restricted by DOM authorization policies. The fix was released in Chrome 152.0.7977.65 or later. Google rated this as Low severity in Chromium's internal classification, though NVD assessed it as Medium.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 for Windows/Mac and 152.0.7977.64 for Linux

References

Related threats