Executive brief
Google Chrome is a widely-used web browser that processes untrusted content from the internet. An incorrect authorization flaw in the Network component allows a remote attacker to bypass system access restrictions by crafting a malicious webpage, potentially exposing local resources or restricted functionality to unauthorized access.
Technical details
CVE-2026-79199 is an incorrect authorization vulnerability in Google Chrome's Network component prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass system access restrictions via a crafted HTML page. The attack requires no special privileges or authentication, as the attacker simply needs to trick a user into visiting a malicious webpage. This vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65