SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79000

MEDIUM · CVSS 4.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Improper input validation in DeviceBoundSessionCredentials in Google Chrome versions prior to 152.0.7977.65 allows remote attackers to exploit crafted network traffic, potentially bypassing web origin policy through social engineering tactics. While the severity is classified as low, organizations using affected Chrome versions should prioritize updating to mitigate the risk of unauthorized access to sensitive data. Users and administrators should remain vigilant against social engineering attempts that could leverage this vulnerability.

CVE
CVE-2026-79000
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%
Chrome

Original NVD Description

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

Related CVEs

Other vulnerabilities affecting the same vendor(s)