DIRAS TAKE
Urgent: update Chrome to 152.0.7977.65 immediately — the flaw lets an attacker bypass access controls if a user loads a crafted page, so treat exposed or user-facing browsers as high priority.
What is CVE-2026-79090?
A remote attacker can bypass system access restrictions in Google Chrome by convincing a user to open a specially crafted HTML page, allowing privilege escalation on the affected browser; this is tracked as CVE-2026-79090. The vulnerability affects Chrome releases prior to 152.0.7977.65 and is fixed in 152.0.7977.65. Exploitation relies on social engineering to get a target to load the malicious page; no separate account or elevated privileges are required beyond the user visiting the content. The weakness is classified as CWE-269 (Improper Privilege Management).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.65 – before 152.0.7977.65 | 152.0.7977.65 |
Is CVE-2026-79090 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-79090
- Apply the vendor update: upgrade Chrome to 152.0.7977.65.
- Block or restrict access to untrusted web content and reduce exposure to user-facing browsing where possible.
- Educate users to avoid opening untrusted links or pages and treat unexpected webpages with caution.
- Monitor browser crash logs and unusual privilege changes for signs of exploitation.
Frequently asked questions
Is CVE-2026-79090 being actively exploited?
There are no public reports of active exploitation of CVE-2026-79090 as of 2026-09-29.
Which Chrome versions are affected by CVE-2026-79090?
Chrome versions prior to 152.0.7977.65 are affected; the issue is fixed in 152.0.7977.65.
Is there a patch for CVE-2026-79090?
Yes. Google released a fix in Chrome 152.0.7977.65; update affected installations to that version or later.
Does CVE-2026-79090 require authentication?
No. The flaw is exploited by getting a user to load a crafted HTML page, so it relies on social engineering rather than prior authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-79090
- cve.org/CVERecord?id=CVE-2026-79090
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- issues.chromium.org/issues/517673944
- All Google CVEs on CVE Radar
- CVEs published in September 2026