Junglewise Threat Intelligence

CVE-2026-79185: Google Chrome information leak in DOM

CVE-2026-79185 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that processes and displays web pages. A flaw in Chrome's DOM (Document Object Model) implementation allows attackers to leak sensitive information and bypass web origin policies—security boundaries that prevent one website from accessing another's data—by sending a specially crafted HTML page. This could enable attackers to steal user credentials, session tokens, or other sensitive data from visited websites.

Technical details

This is an information disclosure vulnerability in Chrome's DOM implementation (CVE-2026-79185) that allows bypassing the same-origin policy, a fundamental browser security mechanism. The vulnerability requires only that a user visit a malicious or compromised web page; no authentication or special browser configuration is needed. An attacker can craft a malicious HTML page that, when loaded in the victim's browser, reads sensitive data from other origins or bypasses cross-origin restrictions. The vulnerability affects Chrome versions prior to 152.0.7977.65, and a patch is available in Chrome 152 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats