Junglewise Threat Intelligence

CVE-2026-79220: Google Chrome information leak in Network component

CVE-2026-79220 · Severity: medium · CVSS 5.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser deployed across millions of devices. This vulnerability allows an attacker with control over Chrome's renderer process to access sensitive information by tricking users into viewing a crafted web page. A compromised renderer could expose data in transit or stored locally, potentially affecting user privacy and security.

Technical details

CVE-2026-79220 is an information leak vulnerability in Chrome's Network component affecting versions prior to 152.0.7977.65. The vulnerability requires the attacker to have already compromised the renderer process, a sandbox-escaped process within Chrome. The attack vector involves a crafted HTML page that triggers the information leak once the renderer is compromised. The vulnerability allows the attacker to obtain sensitive information from the network layer. Google released a patch in Chrome 152.0.7977.65 on 2026-08-25, addressing this and 326 other security issues.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats