Junglewise Threat Intelligence

CVE-2026-79214: Google Chrome improper input validation in Preload

CVE-2026-79214 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Preload feature contains an input validation flaw that could allow a compromised renderer process to bypass web origin policy, which protects web applications from unauthorized cross-origin access. An attacker who gains control of the renderer process could exploit this to access data or functionality from websites the user visits, potentially exposing sensitive information or session data.

Technical details

This vulnerability is an improper input validation flaw in the Preload mechanism of Google Chrome, affecting versions prior to 152.0.7977.65. The vulnerability requires an attacker to have already compromised the renderer process, at which point a crafted HTML page can bypass the same-origin policy through insufficient validation of preload requests. The impact is limited to scenarios where renderer compromise has already occurred; however, once exploited, it enables cross-origin policy bypass. The fix is available in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats