Junglewise Threat Intelligence

CVE-2026-79249: Google Chrome code injection in Bisection

CVE-2026-79249 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely-used web browser, contained a code injection vulnerability in its Bisection component that could allow an attacker to obtain sensitive information by convincing a user to open a specially crafted file. This vulnerability could lead to exposure of private data or browsing information without the user's knowledge.

Technical details

The vulnerability is a code injection flaw in the Bisection component of Google Chrome versions prior to 152.0.7977.65. The attack requires user interaction—specifically, the user must open a crafted file in Chrome. The vulnerability allows a remote attacker to inject code that executes within the browser context, enabling the disclosure of sensitive information. The vulnerability was patched in Chrome 152.0.7977.65 and later versions, released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats