Junglewise Threat Intelligence

CVE-2026-79203: Google Chrome improper input validation in DevTools

CVE-2026-79203 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's DevTools component had a flaw in validating user input that could allow an attacker who had already compromised the browser's renderer process to bypass site isolation protections—a security mechanism designed to prevent malicious websites from accessing data from other sites. An attacker could exploit this via a crafted HTML page to escape the renderer sandbox and potentially access cross-site data, though the immediate attack prerequisite requires an existing compromise of the renderer.

Technical details

This vulnerability is an improper input validation flaw in Chrome's DevTools component. The root cause lies in insufficient sanitization of input within DevTools, allowing an attacker who has already compromised the renderer process to craft a malicious HTML page that bypasses site isolation. Site isolation is a core Chrome security boundary that isolates each website's data in separate renderer processes. The attack vector requires network access and a prior renderer compromise, making this a multi-stage exploit. A successful attack could allow the attacker to read or manipulate data from other websites. The vulnerability was fixed in Chrome version 152.0.7977.65.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats