Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79151

CVE-2026-79151: Google Chrome Safebrowsing Auth Bypass

CVE-2026-79151 is an authentication bypass flaw in Google Chrome Safebrowsing that lets attackers bypass system access restrictions via crafted files. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-79151 Overview

CVE-2026-79151 is an improper input validation vulnerability [CWE-20] in the Safe Browsing component of Google Chrome. The flaw affects Chrome versions prior to 152.0.7977.65. A remote attacker can bypass system access restrictions by delivering a crafted file to a target user. Chromium assigned this issue a Medium security severity rating.

The vulnerability weakens a browser-layer security control that normally warns users about dangerous downloads and restricts access to sensitive system resources. Successful exploitation requires user interaction with an attacker-supplied file.

Critical Impact

A remote attacker can bypass Safe Browsing access restrictions through a crafted file, undermining a security boundary that protects users from malicious downloads.

Affected Products

  • Google Chrome for Desktop versions prior to 152.0.7977.65
  • Chromium-based browsers incorporating the vulnerable Safe Browsing component
  • Downstream distributions that had not yet integrated the Chrome 152 stable channel update

Discovery Timeline

  • 2026-08-25 - CVE-2026-79151 published to the National Vulnerability Database
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-79151

Vulnerability Analysis

The vulnerability resides in Chrome's Safe Browsing subsystem, which validates downloaded files and enforces restrictions on how those files interact with the underlying system. Improper input validation in this code path allows a specially crafted file to slip past checks that would normally block or warn on access attempts.

By bypassing these restrictions, an attacker gains a foothold to influence system-level behavior that Safe Browsing was designed to prevent. The classification maps to [CWE-20], indicating that the component fails to correctly validate or sanitize input properties of the delivered file before acting on it.

The EPSS model estimates a low near-term exploitation probability, and no public proof-of-concept or in-the-wild exploitation has been reported at the time of publication.

Root Cause

The root cause is insufficient validation of file attributes processed by the Safe Browsing component. When Chrome evaluates a file against its access restriction logic, malformed or unexpected input is not fully rejected. This causes the enforcement decision to diverge from the intended security policy. See the Chromium Issue Tracker Entry for additional context once the report is made public.

Attack Vector

Exploitation requires a remote attacker to deliver a crafted file to the victim. Typical delivery paths include a malicious web page hosting the file, an email attachment, or a link shared through messaging platforms. Once the user retrieves the file, the flawed validation logic in Safe Browsing fails to enforce the intended access restriction, enabling the bypass.

The vulnerability is described in prose only because no verified proof-of-concept code has been published. Refer to the Google Chrome Desktop Update advisory for vendor detail.

Detection Methods for CVE-2026-79151

Indicators of Compromise

  • Chrome browser processes on endpoints reporting versions earlier than 152.0.7977.65 after the patch window
  • Downloads of files with unusual extensions or mismatched MIME types that were not flagged by Safe Browsing
  • Post-download child process creation from chrome.exe invoking scripting hosts, cmd.exe, or powershell.exe

Detection Strategies

  • Inventory installed Chrome versions across the fleet and alert on hosts running builds below 152.0.7977.65
  • Correlate browser download telemetry with subsequent file execution events to surface bypasses of expected user warnings
  • Monitor for crafted file formats delivered from newly registered or low-reputation domains

Monitoring Recommendations

  • Ingest browser and endpoint telemetry into a centralized data lake to enable version and behavior analytics
  • Track Safe Browsing warning suppression or unexpected download completions in enterprise browser reporting
  • Baseline normal file-type download patterns per user group and alert on deviations following the CVE disclosure

How to Mitigate CVE-2026-79151

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later on all managed endpoints
  • Force-restart Chrome after policy deployment to ensure the patched binary is loaded
  • Audit Chromium-based browsers (Edge, Brave, Opera, Vivaldi) for corresponding upstream updates

Patch Information

Google addressed CVE-2026-79151 in the Chrome stable channel release documented in the Google Chrome Desktop Update. Administrators should deploy Chrome 152.0.7977.65 or later. Enterprises using managed update policies should verify that automatic updates are enabled and that endpoints have restarted the browser to apply the fix.

Workarounds

  • Restrict download of high-risk file types at the web proxy or secure web gateway until patching completes
  • Enforce enterprise policies that require Safe Browsing Enhanced Protection to remain enabled
  • Limit user privileges so that files delivered via the browser cannot access sensitive system resources
bash
# Verify installed Chrome version on Windows endpoints
reg query "HKLM\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Verify installed Chrome version on macOS endpoints
defaults read /Applications/Google\ Chrome.app/Contents/Info CFBundleShortVersionString

# Verify installed Chrome version on Linux endpoints
google-chrome --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.