Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79253

CVE-2026-79253: Google Chrome Information Disclosure Flaw

CVE-2026-79253 is an information disclosure vulnerability in Google Chrome on Windows that allows attackers to leak sensitive data through social engineering. This post explains its technical details, affected versions, and mitigation steps.

Published:

CVE-2026-79253 Overview

CVE-2026-79253 is an improper input validation vulnerability [CWE-20] in the Network component of Google Chrome on Windows. The flaw affects Chrome versions prior to 152.0.7977.65. A remote attacker can leak sensitive information by convincing a user to visit a crafted HTML page. Exploitation requires user interaction and social engineering, but no privileges or authentication. Chromium engineers rated the security severity as Low, while the CVSS Base Score of 6.5 reflects the potential confidentiality impact.

Critical Impact

Successful exploitation allows a remote attacker to read sensitive information from the browser context through a maliciously crafted web page.

Affected Products

  • Google Chrome on Windows prior to 152.0.7977.65
  • Microsoft Windows systems running vulnerable Chrome builds
  • Chromium-based deployments incorporating the affected Network component

Discovery Timeline

  • 2026-08-25 - CVE-2026-79253 published to the National Vulnerability Database
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-79253

Vulnerability Analysis

The vulnerability resides in the Network component of Google Chrome on Windows. The component fails to properly validate input processed during network operations. An attacker hosts a crafted HTML page and lures a user to visit it. Once loaded, the page triggers the flawed input handling path and causes Chrome to expose sensitive data that should remain isolated from the origin. The confidentiality impact is high, but integrity and availability are unaffected. The attack completes over the network with low complexity and no authentication, though it requires user interaction to load the malicious page. EPSS currently estimates a low probability of near-term exploitation.

Root Cause

The root cause is improper input validation [CWE-20] in the Chrome Network stack. The affected code path does not sufficiently constrain or sanitize attacker-controlled input before consuming it in a security-sensitive network operation. This gap enables cross-context data disclosure when processing a crafted response or resource.

Attack Vector

An attacker delivers a crafted HTML page through phishing, malvertising, or a compromised site. When the victim opens the page in a vulnerable Chrome build on Windows, the embedded content coerces the Network component into leaking data across origin or context boundaries. No authentication or elevated privileges are required. Technical specifics are restricted; see Chromium Issue Tracker #533511921 for tracking details.

Detection Methods for CVE-2026-79253

Indicators of Compromise

  • Chrome browser processes on Windows endpoints running versions earlier than 152.0.7977.65
  • User navigation events to newly registered or low-reputation domains hosting HTML content immediately preceding anomalous outbound requests
  • Unexpected cross-origin resource fetches or data exfiltration patterns originating from Chrome renderer or network service processes

Detection Strategies

  • Inventory installed Chrome versions across Windows fleets and flag hosts below 152.0.7977.65
  • Correlate browser telemetry with URL reputation feeds to identify visits to crafted pages associated with information-disclosure lures
  • Monitor for anomalous outbound traffic patterns from browser processes, including unusual request sizes or destinations following page loads

Monitoring Recommendations

  • Enable browser management policies that report Chrome version and update status to a central console
  • Ingest endpoint and DNS telemetry into a SIEM to alert on interactions with known phishing infrastructure
  • Track Chrome auto-update health and alert when devices fall behind the Stable channel baseline

How to Mitigate CVE-2026-79253

Immediate Actions Required

  • Update Google Chrome on all Windows endpoints to version 152.0.7977.65 or later
  • Verify enterprise update policies are not blocking or deferring the Chrome Stable channel
  • Communicate phishing awareness guidance to users, emphasizing that the exploit requires opening a crafted page

Patch Information

Google addressed the flaw in the Chrome Stable channel update referenced in the Google Chrome Stable Update advisory. Install Chrome 152.0.7977.65 or later on Windows. Restart the browser after the update to complete deployment.

Workarounds

  • Restrict browsing to trusted sites using enterprise URL allowlists until patching completes
  • Deploy web content filtering and DNS-layer controls to block access to known malicious domains
  • Enforce Chrome group policies that require automatic updates and prevent version pinning to vulnerable builds
bash
# Verify installed Chrome version on Windows
reg query "HKLM\Software\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Enforce Chrome auto-update via Group Policy (example registry keys)
reg add "HKLM\Software\Policies\Google\Update" /v UpdateDefault /t REG_DWORD /d 1 /f
reg add "HKLM\Software\Policies\Google\Update" /v AutoUpdateCheckPeriodMinutes /t REG_DWORD /d 60 /f

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.