Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-78980

CVE-2026-78980: Google Chrome ReaderMode Auth Bypass Flaw

CVE-2026-78980 is an authentication bypass vulnerability in Google Chrome ReaderMode that allows attackers to bypass web origin policy through social engineering. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-78980 Overview

CVE-2026-78980 is an improper input validation vulnerability [CWE-20] in the ReaderMode component of Google Chrome. Versions prior to 152.0.7977.65 allow a remote attacker to bypass the web origin policy and reach a privileged page through a crafted HTML page. Exploitation requires user interaction and social engineering, which limits mass exploitation scenarios. Chromium security engineers rated the underlying issue as Low severity, while the National Vulnerability Database assigned a Medium CVSS rating.

Critical Impact

Successful exploitation lets a remote attacker cross the web origin boundary from an attacker-controlled page into a Chrome-privileged context, weakening browser sandbox guarantees.

Affected Products

  • Google Chrome desktop versions prior to 152.0.7977.65
  • Chromium-based browsers incorporating the vulnerable ReaderMode code
  • Downstream distributions that had not yet integrated the Stable channel update

Discovery Timeline

  • 2026-08-25 - CVE-2026-78980 published to the National Vulnerability Database
  • 2026-08-27 - Last updated in NVD database

Technical Details for CVE-2026-78980

Vulnerability Analysis

The flaw resides in Chrome's ReaderMode feature, which reformats article content for easier reading. ReaderMode fails to validate untrusted input from a crafted HTML page before rendering it inside a privileged browser context. An attacker who convinces a user to invoke ReaderMode on a malicious page can smuggle content across the web origin boundary. The result is a limited integrity impact on the privileged page, without direct confidentiality or availability compromise. The vulnerability is categorized as improper input validation and is tracked upstream in Chromium Issue Tracker #523237735.

Root Cause

ReaderMode reparses page content and injects it into an internal Chrome page. The pipeline does not sufficiently sanitize or constrain the origin of the reparsed content. Content that should remain confined to the source web origin is treated as if it belonged to the privileged ReaderMode page. This mismatch violates the same-origin model enforced elsewhere in the renderer.

Attack Vector

Exploitation is remote over the network but requires user interaction. The attacker hosts a crafted HTML page and uses social engineering to lure the target to open it and activate ReaderMode. Once ReaderMode renders the crafted content, attacker-controlled markup or script gains a foothold in a page that operates with elevated Chrome privileges. No authentication, credentials, or prior access are required.

No public proof-of-concept has been released. Refer to the Chromium Issue Tracker #523237735 and the Google Chrome Stable Update announcement for vendor detail.

Detection Methods for CVE-2026-78980

Indicators of Compromise

  • Chrome installations reporting versions earlier than 152.0.7977.65 in inventory or telemetry.
  • Browser history or proxy logs showing ReaderMode activation (chrome-distiller:// URLs) shortly after navigation to unfamiliar external HTML pages.
  • Unexpected navigations from ReaderMode-rendered pages to Chrome internal or privileged URLs.

Detection Strategies

  • Query endpoint inventory for outdated Chrome builds and flag any host on a version older than 152.0.7977.65.
  • Inspect web proxy and DNS logs for user-initiated visits to attacker-controlled HTML pages followed by chrome-distiller:// activity.
  • Correlate phishing email delivery with subsequent Chrome ReaderMode usage on the recipient endpoint.

Monitoring Recommendations

  • Track Chrome version compliance continuously across managed endpoints and alert on drift below the patched build.
  • Monitor for anomalous child processes or renderer crashes originating from Chrome ReaderMode contexts.
  • Ingest browser and proxy telemetry into a centralized data lake for correlation with phishing and social engineering indicators.

How to Mitigate CVE-2026-78980

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later on all managed endpoints.
  • Restart Chrome after the update to ensure the patched binaries are active in every user session.
  • Push the update through enterprise browser management to reach endpoints that skip user-initiated updates.

Patch Information

Google addressed the vulnerability in the Chrome Stable channel with version 152.0.7977.65. Deployment details are documented in the Google Chrome Stable Update announcement. Chromium-based browsers should apply the equivalent upstream fix referenced in Chromium Issue Tracker #523237735.

Workarounds

  • Disable or restrict ReaderMode via enterprise policy where operational impact is acceptable.
  • Reinforce user awareness training focused on social engineering lures that request ReaderMode activation on unfamiliar pages.
  • Apply URL filtering and email security controls to block delivery of attacker-controlled HTML pages used in phishing campaigns.
bash
# Verify installed Chrome version on managed endpoints
google-chrome --version
# Expected output should be 152.0.7977.65 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.