Executive brief
Google Chrome is a widely-used web browser relied upon by billions of users for everyday internet access. A missing authorization check in Chrome's HTTP2 implementation could allow an attacker to send specially crafted network traffic that leaks sensitive information accessible to the user. This could expose browsing data, cached credentials, or other private user information without requiring user interaction or special privileges.
Technical details
A missing authorization vulnerability exists in Google Chrome's HTTP2 implementation, where insufficient validation of authorization checks allows a remote attacker to craft malicious network traffic that bypasses access controls. The vulnerability requires network-level access to intercept or manipulate HTTP2 streams, but does not require the user to be authenticated or perform any specific action. By exploiting this flaw, an attacker can leak sensitive information handled by the HTTP2 protocol handler. Google patched this issue in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65