Junglewise Threat Intelligence

CVE-2026-79259: Google Chrome improper input validation in Safebrowsing

CVE-2026-79259 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome includes a Safebrowsing component that protects users from malicious websites and files. A flaw in input validation allows an attacker to bypass system access restrictions by supplying a specially crafted file, potentially enabling unauthorized access to protected resources or data on the user's system.

Technical details

CVE-2026-79259 is an improper input validation vulnerability in the Safebrowsing component of Google Chrome. The flaw permits a remote attacker to bypass system access restrictions via a crafted file. The vulnerability is network-reachable and requires the user to interact with a malicious file. The attack vector is primarily network-based, as the attacker can deliver the crafted file to the target. Chrome 152.0.7977.65 and later versions contain the fix. This is a Medium severity issue per Chromium's internal classification.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats