Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79181

CVE-2026-79181: Google Chrome Information Disclosure Flaw

CVE-2026-79181 is an information disclosure vulnerability in Google Chrome's Glic component that allows attackers to obtain sensitive data through crafted HTML pages. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-79181 Overview

CVE-2026-79181 is an observable discrepancy vulnerability [CWE-203] in the Glic component of Google Chrome. The flaw affects Chrome versions prior to 152.0.7977.65. A remote attacker can obtain sensitive information by convincing a user to visit a crafted HTML page. Chromium classifies the underlying security severity as Low, while the National Vulnerability Database rates the CVSS v3.1 score at 5.3 (Medium).

The issue relies on observable behavioral differences that leak information across security boundaries. Successful exploitation requires user interaction and has high attack complexity, limiting broad opportunistic abuse.

Critical Impact

A remote attacker can extract sensitive information from a victim's browser through a crafted HTML page rendered by a vulnerable Chrome build.

Affected Products

  • Google Chrome for Desktop versions prior to 152.0.7977.65
  • Chromium-based builds incorporating the vulnerable Glic component
  • Downstream browsers embedding pre-patch Chromium releases

Discovery Timeline

  • 2026-08-25 - CVE-2026-79181 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-79181

Vulnerability Analysis

The vulnerability is an observable discrepancy issue [CWE-203] in Glic, a Chrome browser component. Observable discrepancy flaws expose information because the software's behavior, timing, or output differs based on the value of protected data. An attacker measures those differences and infers information that should remain inaccessible.

In this case, a crafted HTML page can induce measurable variations that reveal sensitive information to a remote page. The vulnerability affects confidentiality only. It does not permit code execution, data modification, or denial of service against the browser process.

Exploitation requires the victim to load attacker-controlled content, and attack complexity is high. This aligns with side-channel style disclosures where the attacker must control page structure and measurement conditions precisely to extract useful signal.

Root Cause

The root cause is a behavioral discrepancy within Glic that varies based on protected state. Because inputs, timings, or responses differ observably, an attacker running JavaScript in a same-context page can infer values that Chrome should isolate. Google's patch in Chrome 152.0.7977.65 removes the discrepancy so that the observable behavior no longer depends on the protected data.

Attack Vector

An attacker hosts or injects a malicious HTML page and lures a user to open it in a vulnerable Chrome build. The page issues carefully structured requests or DOM operations against Glic and measures the resulting responses. Repeated measurements allow the attacker to reconstruct sensitive information from the browsing session. No credentials or privileges are required, but user interaction is mandatory. See the Chromium Issue #506539337 and the Google Chrome Stable Update advisories for vendor context.

Detection Methods for CVE-2026-79181

Indicators of Compromise

  • Browser sessions on Chrome builds earlier than 152.0.7977.65 visiting untrusted or newly registered domains
  • Web pages generating unusually high volumes of repeated timing measurements or subresource probes against Glic endpoints
  • Outbound telemetry from Chrome renderers to attacker-controlled infrastructure following visits to unknown HTML content

Detection Strategies

  • Inventory endpoint Chrome versions and flag installations reporting a version below 152.0.7977.65
  • Correlate proxy or DNS logs with browser version telemetry to identify vulnerable users interacting with low-reputation domains
  • Hunt for JavaScript patterns performing repetitive high-resolution timing measurements consistent with side-channel probing

Monitoring Recommendations

  • Ingest browser and endpoint version telemetry into a central data lake to track patch coverage over time
  • Monitor web gateway logs for pages loading atypical Glic-related resources from untrusted origins
  • Alert on Chrome auto-update failures that leave hosts pinned to pre-patch builds

How to Mitigate CVE-2026-79181

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later across all managed endpoints
  • Verify Chrome auto-update is enabled and functional; force restart of Chrome to complete pending updates
  • Audit Chromium-based browsers and applications for embedded builds that predate the fix

Patch Information

Google released the fix in the Chrome Stable channel update to version 152.0.7977.65. Administrators should reference the Google Chrome Stable Update advisory and confirm deployment through enterprise management tooling. Restart Chrome after updating to activate the patched binaries.

Workarounds

  • Restrict browsing to trusted sites through enterprise web filtering until patches are deployed
  • Enforce Chrome enterprise policies that block execution of untrusted HTML content in sensitive contexts
  • Provide user awareness guidance to avoid opening HTML attachments or links from unknown senders
bash
# Verify Chrome version on managed endpoints
google-chrome --version

# Windows registry policy to enforce minimum Chrome version and updates
reg add "HKLM\Software\Policies\Google\Update" /v UpdateDefault /t REG_DWORD /d 1 /f

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.