Junglewise Threat Intelligence

CVE-2026-79212: Google Chrome missing authorization in Passwords

CVE-2026-79212 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's password manager allows authenticated password access without proper authorization checks. A remote attacker who has already compromised Chrome's rendering engine could exploit this via social engineering and a specially crafted webpage to bypass browser security controls and access stored passwords, potentially leading to credential theft and account compromise.

Technical details

This vulnerability is a missing authorization check in Chrome's password management system. The attack requires two preconditions: the renderer process must already be compromised (e.g., via another exploit or code execution vulnerability), and the victim must be socially engineered to interact with a malicious HTML page. By exploiting the missing authorization in the passwords component, an attacker can bypass web origin policy restrictions and access sensitive password data. The vulnerability was classified as High severity by the Chromium security team and is fixed in Chrome version 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats