Junglewise Threat Intelligence

CVE-2026-79260: Google Chrome improper input validation in Cookies

CVE-2026-79260 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's cookie handling mechanism had insufficient validation of user input, allowing an attacker with access to the browser's rendering process to bypass website origin security policies. This could permit unauthorized access to or manipulation of website data and cookies, potentially compromising user accounts and sensitive information stored by websites.

Technical details

The vulnerability is an improper input validation flaw in Google Chrome's cookie handling code affecting versions prior to 152.0.7977.65. A remote attacker who had already compromised the renderer process could exploit this weakness by crafting a malicious HTML page to bypass web origin policy—a fundamental security boundary that isolates data between different websites. The attack requires prior renderer process compromise, limiting the attack surface but allowing privilege escalation or lateral movement within the browser. Patches are available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats