Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79021

CVE-2026-79021: Google Chrome Authorization Bypass Vulnerability

CVE-2026-79021 is an authorization bypass flaw in Google Chrome InterestGroups that lets attackers with compromised renderer access bypass system restrictions via PDF files. This post covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-79021 Overview

CVE-2026-79021 is a missing authorization vulnerability [CWE-862] in the InterestGroups component of Google Chrome. The flaw affects Chrome versions prior to 152.0.7977.65. A remote attacker who has already compromised the renderer process can bypass system access restrictions by delivering a crafted PDF file. Google's Chromium project rated the underlying security severity as Low, while the assigned CVSS 3.1 score is 6.5. Exploitation requires user interaction, typically opening the crafted PDF. The InterestGroups API is part of Chrome's Privacy Sandbox implementation supporting the Protected Audience API.

Critical Impact

A compromised renderer process can bypass authorization checks in the InterestGroups component via a crafted PDF, allowing unauthorized modification of state protected by system access restrictions.

Affected Products

  • Google Chrome versions prior to 152.0.7977.65
  • Chromium-based browsers incorporating vulnerable InterestGroups code
  • Desktop Chrome Stable channel builds preceding the August 2026 update

Discovery Timeline

  • 2026-08-25 - CVE-2026-79021 published to NVD
  • 2026-08-27 - Last updated in NVD database

Technical Details for CVE-2026-79021

Vulnerability Analysis

The vulnerability resides in Chrome's InterestGroups implementation, a component of the Privacy Sandbox Protected Audience API. The component fails to perform sufficient authorization checks when processing requests originating from a compromised renderer. An attacker who has already achieved code execution within a renderer can craft a PDF that triggers InterestGroups operations outside the renderer's expected authority boundary. The result is a bypass of system access restrictions that normally gate these operations. Because Chrome relies on the browser process to enforce cross-origin and privilege boundaries, missing authorization in this pathway erodes site isolation guarantees.

Root Cause

The root cause is classified as [CWE-862] Missing Authorization. Code paths within InterestGroups accept requests from the renderer process without confirming that the caller holds the required privileges. This trust assumption breaks when the renderer itself is compromised through a chained exploit. The condition is a design-level access control gap rather than a memory corruption issue.

Attack Vector

Exploitation is a two-stage chain. First, an attacker must compromise the Chrome renderer process, typically through a separate rendering-engine vulnerability. Second, the attacker delivers a crafted PDF that the victim opens in Chrome. The PDF drives interactions with the InterestGroups interface to reach the unprotected code path. Successful exploitation impacts integrity by allowing state changes that should require higher privileges. Confidentiality and availability are not directly affected according to the CVSS vector.

No public proof-of-concept code is available. Technical specifics are tracked in Chromium Issue #533060125 and the Google Chrome Stable Update announcement.

Detection Methods for CVE-2026-79021

Indicators of Compromise

  • Chrome processes loading unexpected PDF files from untrusted origins followed by anomalous inter-process communication with the browser process
  • Renderer processes exhibiting behavior consistent with prior exploitation, such as spawning child processes or accessing unexpected file paths
  • Endpoints running Chrome builds older than 152.0.7977.65 while browsing high-risk content

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag any build below 152.0.7977.65
  • Monitor for renderer sandbox escape indicators, which are prerequisites for reaching this vulnerability
  • Alert on Chrome opening PDFs delivered from newly registered or low-reputation domains

Monitoring Recommendations

  • Correlate browser telemetry with endpoint process trees to identify Chrome renderer processes performing privileged operations
  • Ingest Chrome update logs and enterprise policy telemetry into the SIEM to confirm patch deployment status
  • Track PDF download events paired with subsequent outbound network activity from the browser process

How to Mitigate CVE-2026-79021

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later on all managed endpoints
  • Force-restart Chrome after applying the update so the patched binary is loaded into active sessions
  • Verify Chromium-based browsers such as Edge, Brave, and Opera have absorbed the upstream fix

Patch Information

Google addressed CVE-2026-79021 in Chrome Stable 152.0.7977.65. Details are published in the Google Chrome Stable Update advisory. Enterprises using Chrome Browser Cloud Management or group policy should confirm auto-update is enabled and that the target version is deployed across the fleet.

Workarounds

  • Restrict opening of PDFs from untrusted sources by routing them through a dedicated PDF reader with sandboxing enabled
  • Disable Chrome's Privacy Sandbox trial features where operationally acceptable via enterprise policy
  • Apply site isolation and strict enterprise policies to limit renderer capabilities until the patch is deployed
bash
# Verify Chrome version on Linux endpoints
google-chrome --version

# Windows: check installed version via registry
reg query "HKLM\Software\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Enterprise policy example: enforce minimum Chrome version via GPO
# Registry path: HKLM\Software\Policies\Google\Chrome
# Value: TargetVersionPrefix = "152.0.7977.65"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.