SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79072

HIGH · CVSS 8.1 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in Google Chrome prior to version 152.0.7977.65 allows remote attackers to exploit improper state validation in the Performance component, potentially enabling them to read memory within the sandbox through a specially crafted HTML page. This could lead to unauthorized information disclosure, making it critical for users and organizations relying on Chrome for secure browsing to prioritize updates. Security teams should assess their environments for affected versions and apply necessary patches to mitigate this risk.

CVE
CVE-2026-79072
Severity
HIGH
CVSS
8.1
EPSS
0.31%
Chrome

Original NVD Description

Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)