Junglewise Threat Intelligence

CVE-2026-79255: Google Chrome WebRTC improper input validation

CVE-2026-79255 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebRTC component contains improper input validation that allows an attacker who has already compromised the browser's rendering process to bypass web origin policy restrictions. This could enable attackers with renderer-level access to bypass cross-origin protections and access sensitive data from different websites, though successful exploitation requires a prior compromise of the browser process itself.

Technical details

The vulnerability is an improper input validation flaw in Chrome's WebRTC implementation affecting versions prior to 152.0.7977.65. The attack vector requires the attacker to have already compromised the renderer process, and then exploit this input validation weakness to bypass web origin policy (same-origin policy). An attacker who has achieved renderer process compromise can craft a malicious HTML page that, when processed, bypasses origin restrictions. The fix is available in Chrome version 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats