Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-79090: Google Chrome (pre‑152) can be tricked to bypass controls
CVE-2026-79090 · published 9 days ago
Summary
Older versions of Google Chrome may let a specially crafted webpage bypass the normal security checks that keep users from accessing restricted parts of the system. If someone convinces a user to open such a page, the attacker could gain more access than intended. Update Chrome to the latest version to close this gap.
What to do
- Update google chrome to version 152.0.7977.65 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | chrome | < 152.0.7977.65 | |
| Debian:11 | debian | chromium | All versions |
| Debian:12 | debian | chromium | All versions |
| Debian:13 | debian | chromium | All versions |
| Debian:14 | debian | chromium | All versions |
Original advisory text
Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. ...
Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published25 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Monitor software like this
Free during beta