Junglewise Threat Intelligence

CVE-2026-79242: Google Chrome HTML observable discrepancy information leak

CVE-2026-79242 · Severity: medium · CVSS 5.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by millions of users to access websites and web applications. A vulnerability in how Chrome renders HTML allows a remote attacker to craft a malicious web page that reveals sensitive information to the attacker. An affected user visiting such a page could have data exposed without any visible indication.

Technical details

This vulnerability is an observable discrepancy in HTML rendering in Google Chrome prior to version 152.0.7977.65. It allows a remote attacker to craft a specially designed HTML page that exploits a difference in how the browser renders content, enabling information disclosure. The attack requires no authentication or user interaction beyond visiting a malicious webpage. The vulnerability was fixed in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats