Junglewise Threat Intelligence

CVE-2026-79192: Google Chrome improper input validation in Variations

CVE-2026-79192 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Variations component, which manages feature flags and experimental configuration distribution, contains improper input validation that allows a remote attacker to bypass web origin policy protections. This could enable attackers to circumvent security boundaries that prevent scripts and resources from one website from accessing data or functionality on another, potentially leading to unauthorized access to sensitive user data or credential theft.

Technical details

The vulnerability exists in Chrome's Variations system prior to version 152.0.7977.65 due to improper input validation when processing network traffic. An attacker can craft malicious network traffic to bypass the same-origin policy, a fundamental web security mechanism that isolates web origins from each other. The attack requires network-level access to deliver crafted packets but does not require user authentication or interaction. Successful exploitation allows an attacker to bypass web origin restrictions and access cross-origin resources. The vulnerability is patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats