Executive brief
Google Chrome is a web browser used by billions of people to access the internet. A flaw in how Chrome handles CSS (the styling code on web pages) allows attackers to craft malicious web pages that leak sensitive information to unauthorized parties. Users who visit a compromised or attacker-controlled website could have confidential data exposed.
Technical details
CVE-2026-79234 is a CSS injection vulnerability in Google Chrome prior to version 152.0.7977.65 that allows remote attackers to obtain sensitive information. The vulnerability is triggered via a crafted HTML page, requiring no user authentication but relying on the user visiting a malicious or compromised website. An attacker can exploit this by injecting malicious CSS code to extract information that should not be accessible. The vulnerability has been fixed in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65