Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-78941

CVE-2026-78941: Google Chrome Information Disclosure Flaw

CVE-2026-78941 is an information disclosure vulnerability in Google Chrome that allows attackers to bypass site isolation. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-78941 Overview

CVE-2026-78941 is an information disclosure vulnerability in the Core component of Google Chrome prior to version 152.0.7977.65. A remote attacker who has already compromised the renderer process can bypass site isolation using a crafted HTML page. The flaw is categorized under CWE-200: Exposure of Sensitive Information to an Unauthorized Actor. Google assigned this issue a Chromium security severity of Medium. Site isolation is a foundational browser security boundary that separates content from different origins into distinct processes. Bypassing it allows cross-origin data leakage that violates the same-origin policy.

Critical Impact

A compromised renderer process can read data belonging to other origins, undermining the browser's primary defense against Spectre-class and cross-site data theft attacks.

Affected Products

  • Google Chrome Desktop versions prior to 152.0.7977.65
  • Chromium-based browsers incorporating the same Core component
  • All platforms supported by Chrome Stable channel (Windows, macOS, Linux)

Discovery Timeline

  • 2026-08-25 - CVE-2026-78941 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-78941

Vulnerability Analysis

The vulnerability resides in the Core component of Chrome and enables an attacker-controlled renderer to obtain information across site isolation boundaries. Site isolation places documents from different sites into separate operating system processes. It prevents a compromised or malicious renderer from directly accessing memory associated with another site. When this boundary fails, an attacker who already controls a renderer can extract data such as cookies, authenticated resources, or Document Object Model (DOM) content from unrelated origins loaded in the same browser session. Google classifies the issue as Medium severity, reflecting the prerequisite that the renderer must already be compromised through a separate exploit.

Root Cause

The root cause is an information exposure weakness [CWE-200] in Chrome's Core code path responsible for enforcing cross-process origin separation. According to the Chromium Issue Tracker entry #498327743 and the Google Chrome Desktop Update advisory, the affected logic did not adequately isolate certain data structures reachable from a renderer, permitting a crafted page to observe cross-origin state.

Attack Vector

Exploitation requires two stages. First, the attacker must compromise the renderer process, typically through a separate memory-corruption or logic bug in a web engine component. Second, the attacker delivers a crafted HTML page that triggers the flawed code path in Core to bypass site isolation. The result is unauthorized disclosure of data belonging to other sites the victim is browsing. No verified public proof-of-concept code is available at this time. Refer to the Chromium Issue Tracker entry for technical details as they become public.

Detection Methods for CVE-2026-78941

Indicators of Compromise

  • Chrome installations reporting a version string below 152.0.7977.65 in enterprise inventory scans
  • Unexpected renderer process crashes or sandbox violation events preceding cross-origin data access
  • Outbound requests from browser processes containing content that should be isolated to another origin

Detection Strategies

  • Inventory endpoints using software asset management to identify Chrome builds prior to 152.0.7977.65
  • Correlate browser process telemetry with suspicious child-process behavior indicative of a renderer compromise chain
  • Monitor for delivery of obfuscated or exploit-laden HTML pages via web proxy and email gateway logs

Monitoring Recommendations

  • Track Chrome version distribution across the fleet and alert on out-of-date installations
  • Ingest endpoint browser telemetry into the security data lake to enable retrospective hunting once further indicators are published
  • Review Chromium security release notes on each Stable channel update and re-baseline detection content

How to Mitigate CVE-2026-78941

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later on all managed endpoints
  • Force browser restarts through management tooling to ensure the patched binary is loaded
  • Verify that Chromium-derived browsers in the environment have incorporated the upstream fix

Patch Information

Google addressed CVE-2026-78941 in Chrome Stable channel version 152.0.7977.65. Details of the release are documented in the Google Chrome Stable Channel Update for Desktop. The corresponding Chromium tracking entry is available at Chromium Issue Tracker #498327743. Enterprise administrators should deploy the update through Google Update, Chrome Browser Cloud Management, or their existing patch management pipeline.

Workarounds

  • No vendor-supplied workaround exists; applying the patch is the only supported remediation
  • Restrict browsing to trusted sites through web proxy policies until the update is deployed
  • Enforce enterprise browser policies that disable unnecessary experimental features to reduce renderer attack surface
bash
# Verify installed Chrome version on Linux endpoints
google-chrome --version

# Windows: query the installed version from the registry
reg query "HKLM\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# macOS: read the CFBundleShortVersionString
defaults read "/Applications/Google Chrome.app/Contents/Info.plist" CFBundleShortVersionString

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.