CVE-2026-79186: Incorrect authorization in Google Chrome
Description
CVE-2026-79186 is a vulnerability in Google Chrome's Network component prior to version 152.0.7977.65. It involves incorrect authorization that allows a remote attacker who has compromised the renderer process to bypass site isolation using a crafted HTML page. The vulnerability is rated with low severity and has a CVSS score of 3.1. No known exploits are reported in the wild. The vendor advisory does not explicitly state the availability of a patch or fix.
CVSS v3.1
Score 3.1low
Affected software
Chrome
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Google Chrome (CVE-2026-79186) concerns incorrect authorization in the Network component that could allow a remote attacker, with control over the renderer process, to bypass site isolation protections by leveraging a crafted HTML page. The issue affects versions prior to 152.0.7977.65. The CVSS 3.1 base score is 3.1, indicating low severity, with attack vector network, high attack complexity, no privileges required, user interaction required, unchanged scope, and low impact on confidentiality. There is no explicit vendor advisory detail on remediation level or patch availability, but the affected version is identified as 152.0.7977.65, implying that this version addresses the issue.
Potential Impact
The impact is limited to a low-severity bypass of site isolation protections, which could allow an attacker who already controls the renderer process to circumvent security boundaries between sites. There is no indication of direct data confidentiality, integrity, or availability impact beyond this bypass. No known active exploitation has been reported.
Mitigation Recommendations
Since the vulnerability affects versions prior to 152.0.7977.65, updating Google Chrome to version 152.0.7977.65 or later is recommended to remediate this issue. The vendor advisory linked does not explicitly confirm patch status, so users should verify the update status via the official Chrome release notes. No additional mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-08-25T06:11:06.195Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html","vendor":"Google"}]
Threat ID: 6a8df9dbacd9273b49ac718d
Added to database: 08/25/2026, 20:23:55 UTC
Last enriched: 09/07/2026, 15:47:22 UTC
Last updated: 10/08/2026, 06:48:19 UTC
Views: 28
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.