Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-79090: Google Chrome (pre‑152) can be tricked to bypass controls

CVE-2026-79090 · published 9 days ago
Summary

Older versions of Google Chrome may let a specially crafted webpage bypass the normal security checks that keep users from accessing restricted parts of the system. If someone convinces a user to open such a page, the attacker could gain more access than intended. Update Chrome to the latest version to close this gap.

What to do
  • Update google chrome to version 152.0.7977.65 or later.
Affected software
Ecosystem VendorProductAffected versions
google chrome < 152.0.7977.65
Debian:11 debian chromium All versions
Debian:12 debian chromium All versions
Debian:13 debian chromium All versions
Debian:14 debian chromium All versions
Original advisory text
Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. ...
Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published25 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Sources
CVE-2026-79090 · MITRE
Monitor software like this
Free during beta