Junglewise Threat Intelligence

CVE-2026-79205: Google Chrome incorrect authorization in Network component

CVE-2026-79205 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that handles network communications and enforces security boundaries between web origins to protect users from malicious websites. This vulnerability allows a remote attacker to bypass the web origin policy through a crafted HTML page, potentially enabling an attacker to access or manipulate data intended for other websites. The flaw affects Chrome versions prior to 152.0.7977.65 and is fixed in Chrome 152 and later.

Technical details

CVE-2026-79205 is an incorrect authorization vulnerability in the Network component of Google Chrome. An attacker can craft a malicious HTML page that, when loaded by a user, bypasses the browser's same-origin policy (SOP)—the fundamental security boundary that prevents scripts from one origin from accessing resources at another origin. The attack is network-based and requires user interaction (visiting the malicious page). Successful exploitation allows an attacker to read or modify cross-origin data, potentially leading to session hijacking, credential theft, or website defacement. The vulnerability is patched in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats