Junglewise Threat Intelligence

CVE-2026-79272: Google Chrome improper input validation in FindInPage

CVE-2026-79272 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's FindInPage feature contains a flaw that allows an attacker who has already compromised the browser's renderer process to leak sensitive data from other websites via a specially crafted HTML page. This could lead to unauthorized access to cross-origin user data, potentially exposing passwords, personal information, or other confidential content.

Technical details

The vulnerability is classified as improper input validation in the FindInPage component of Google Chrome. The attack requires a compromised renderer process as a precondition, which means an attacker must first achieve code execution within the browser's rendering engine (via another vulnerability or compromise vector). Once the renderer is compromised, the attacker can craft a malicious HTML page that exploits the input validation flaw to leak cross-origin data. The vulnerability was fixed in Chrome 152.0.7977.65 and later versions. The Chromium project classified this as Medium severity.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats