Junglewise Threat Intelligence

CVE-2026-79223: Google Chrome integer overflow in Chromium

CVE-2026-79223 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of people to access websites and applications. An integer overflow flaw in Chromium (the underlying open-source engine) allows a remote attacker to read sensitive memory data within the browser's security sandbox via a crafted file, potentially exposing user credentials, browsing data, or other confidential information stored in memory.

Technical details

An integer overflow vulnerability exists in Chromium, the rendering engine underlying Google Chrome, affecting versions prior to 152.0.7977.65. The flaw permits a remote attacker to read memory inside the Chrome sandbox by crafting and serving a malicious file (e.g., via a web page or email attachment). The attack requires no user authentication but does require user interaction (visiting a malicious site or opening a crafted file). The vulnerability is classified as Low severity by the Chromium project but rated High by external assessors (CVSS 8.8). No evidence of active exploitation in the wild has been reported at this time; the patch is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats