• PATCH AVAILABLE

CVE-2026-79090: privilege management bypass in Google Chrome

A remote attacker can bypass system access restrictions in Google Chrome by convincing a user to open a specially crafted HTML page, allowing privilege escalation on the affected browser; this is tracked as CVE-2026-79090. The vulnerability affects Chrome releases prior to 152.0.7977.65 and is fixed in 152.0.7977.65. Exploitation relies on social engineering to get a target to load the malicious page; no separate account or elevated privileges are required beyond the user visiting the content.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00419
CWE
CWE-269
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: update Chrome to 152.0.7977.65 immediately — the flaw lets an attacker bypass access controls if a user loads a crafted page, so treat exposed or user-facing browsers as high priority.

What is CVE-2026-79090?

A remote attacker can bypass system access restrictions in Google Chrome by convincing a user to open a specially crafted HTML page, allowing privilege escalation on the affected browser; this is tracked as CVE-2026-79090. The vulnerability affects Chrome releases prior to 152.0.7977.65 and is fixed in 152.0.7977.65. Exploitation relies on social engineering to get a target to load the malicious page; no separate account or elevated privileges are required beyond the user visiting the content. The weakness is classified as CWE-269 (Improper Privilege Management).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.65 – before 152.0.7977.65152.0.7977.65

Is CVE-2026-79090 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-79090

  1. Apply the vendor update: upgrade Chrome to 152.0.7977.65.
  2. Block or restrict access to untrusted web content and reduce exposure to user-facing browsing where possible.
  3. Educate users to avoid opening untrusted links or pages and treat unexpected webpages with caution.
  4. Monitor browser crash logs and unusual privilege changes for signs of exploitation.

Frequently asked questions

Is CVE-2026-79090 being actively exploited?

There are no public reports of active exploitation of CVE-2026-79090 as of 2026-09-29.

Which Chrome versions are affected by CVE-2026-79090?

Chrome versions prior to 152.0.7977.65 are affected; the issue is fixed in 152.0.7977.65.

Is there a patch for CVE-2026-79090?

Yes. Google released a fix in Chrome 152.0.7977.65; update affected installations to that version or later.

Does CVE-2026-79090 require authentication?

No. The flaw is exploited by getting a user to load a crafted HTML page, so it relies on social engineering rather than prior authentication.

References