Junglewise Threat Intelligence

CVE-2026-79271: Google Chrome information leak in DOM

CVE-2026-79271 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that processes and displays web content from the internet. An information leak vulnerability in Chrome's Document Object Model (DOM) could allow attackers to trick users into visiting a malicious website and steal sensitive information such as passwords, authentication tokens, or personal data. This vulnerability affects Chrome versions before 152.0.7977.65.

Technical details

This vulnerability is an information leak in the DOM (Document Object Model) component of Google Chrome prior to version 152.0.7977.65. The attack vector relies on social engineering—users must visit a crafted HTML page served by an attacker. The vulnerability allows remote attackers to obtain sensitive information that should be protected or hidden from the page's context. No authentication or elevated privileges are required; only user interaction (visiting a malicious link) is needed. Google patched this issue in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 and later

References

Related threats