Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79272

CVE-2026-79272: Chrome FindInPage Information Disclosure

CVE-2026-79272 is an information disclosure vulnerability in Google Chrome FindInPage feature caused by improper input validation. Attackers with renderer process access can leak cross-origin data. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-79272 Overview

CVE-2026-79272 is an improper input validation vulnerability [CWE-20] in the FindInPage component of Google Chrome. Versions prior to 152.0.7977.65 are affected. A remote attacker who has already compromised the renderer process can leak cross-origin data by serving a crafted HTML page. Chromium classifies the security severity as Medium, while NVD scores it at 3.1 (Low). The flaw undermines Chrome's same-origin policy boundary, exposing content from other origins to attacker-controlled code inside the renderer.

Critical Impact

Attackers with a compromised renderer process can exfiltrate cross-origin data through the FindInPage feature, breaking site isolation guarantees.

Affected Products

  • Google Chrome versions prior to 152.0.7977.65
  • Chromium-based browsers incorporating the affected FindInPage implementation
  • Desktop stable channel builds released before the August 2026 update

Discovery Timeline

  • 2026-08-25 - CVE-2026-79272 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-79272

Vulnerability Analysis

The vulnerability resides in Chrome's FindInPage functionality, which searches the current document for user-supplied text. Improper input validation permits a compromised renderer to influence the search operation across origin boundaries. This defeats the site isolation model that normally prevents one origin from reading another. The attacker must first achieve renderer compromise, which raises the exploitation bar and explains the lower NVD score. User interaction is required, likely through visiting an attacker-controlled page.

Root Cause

The root cause is missing or insufficient validation of input passed to the FindInPage code path. Chromium's issue tracker documents the underlying defect. The component fails to enforce that search operations remain scoped to the requesting origin's data. This allows crafted inputs to reach state associated with other origins loaded into the same process context.

Attack Vector

Exploitation requires two conditions. First, the attacker must already control the renderer process, typically through a prior sandbox-contained bug. Second, the victim must interact with a crafted HTML page. Once both conditions are met, the attacker invokes FindInPage in a way that leaks content from a cross-origin resource. The leaked data can include text, tokens, or other information visible to the renderer that should remain isolated. See the Google Chrome update announcement for the vendor description.

Detection Methods for CVE-2026-79272

Indicators of Compromise

  • Chrome browser processes running versions earlier than 152.0.7977.65 after the patch release window
  • Renderer process crashes or anomalous child-process behavior preceding suspected data exfiltration
  • Outbound network requests from browser hosts containing content from unrelated origins

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag builds below 152.0.7977.65
  • Correlate browser telemetry with proxy logs to identify unexpected cross-origin data patterns leaving endpoints
  • Monitor for chained exploitation, since this bug requires a prior renderer compromise to be useful

Monitoring Recommendations

  • Enable enterprise browser reporting to capture version state and extension inventory continuously
  • Alert on delayed patching where Chrome auto-update is disabled or blocked by policy
  • Track threat intelligence for public proof-of-concept code targeting Chromium FindInPage

How to Mitigate CVE-2026-79272

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later on all managed endpoints
  • Verify that Chrome auto-update services are running and not blocked by group policy or network controls
  • Restart Chrome after the update to ensure the patched binaries are loaded into memory

Patch Information

Google addressed CVE-2026-79272 in Chrome stable channel 152.0.7977.65. Details are published in the stable channel update announcement and the Chromium issue tracker entry. Downstream Chromium-based browsers should apply their vendors' corresponding updates once available.

Workarounds

  • No official workaround replaces patching; prioritize the browser update
  • Reduce exposure by restricting untrusted browsing through segmentation or isolated browsing profiles
  • Enforce site isolation and disable unnecessary extensions that increase renderer attack surface
bash
# Verify installed Chrome version on Windows endpoints
reg query "HKLM\SOFTWARE\WOW6432Node\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Verify installed Chrome version on macOS endpoints
mdls -name kMDItemVersion /Applications/Google\ Chrome.app

# Verify installed Chrome version on Linux endpoints
google-chrome --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.