Junglewise Threat Intelligence

CVE-2026-79246: Google Chrome information leak in DataTransfer

CVE-2026-79246 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser. An information leak vulnerability in Chrome's DataTransfer functionality could allow an attacker to extract sensitive information (such as clipboard data or drag-and-drop content) by tricking a user into visiting a malicious webpage. This could expose confidential data like passwords, personal information, or corporate documents.

Technical details

This vulnerability is an information leak in the DataTransfer component of Google Chrome prior to version 152.0.7977.65. The vulnerability is triggered via a crafted HTML page, suggesting the attack vector is network-based and requires user interaction (visiting a malicious page). An attacker can exploit this to obtain sensitive information exposed through the DataTransfer API. The issue has been patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats