Sceawere

Vulnerability Detail

CVE-2026-79001UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome Bluetooth Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Information leak
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-25T21:17:55.753Z",
  "pubdate": "2026-08-25T21:17:55.753Z",
  "executiveSummary": "This vulnerability involves an information leak within the Bluetooth implementation in Google Chrome for macOS, affecting versions prior to 152.0.7977.65. Classified with a Low severity rating, the flaw permits a remote attacker to exfiltrate sensitive data by leveraging a compromised renderer process.\nExploitation requires a multi-stage approach, combining the initial renderer process compromise with successful social engineering tactics directed at the user. By directing a user to a crafted HTML page, an attacker can bypass standard security boundaries to access information that should remain protected. The vulnerability resides in the interaction between the browser's Bluetooth handling mechanisms and the underlying operating system's sandbox environment. While the necessity of social engineering and prior process compromise limits the immediate risk to the average user, the potential for sensitive data exposure warrants prompt remediation to the latest version of Chromium to ensure robust isolation between web content and local Bluetooth services.",
  "technicalDetails": "The vulnerability exists within the Bluetooth subsystem of Google Chrome on macOS, specifically involving the interface between the web-facing renderer process and the browser's privileged Bluetooth management components. Under normal operating conditions, the browser sandbox is designed to restrict access to local hardware peripherals to prevent unauthorized telemetry or data exfiltration. However, a flaw in how the Bluetooth API processes requests allows for the potential exposure of sensitive data when the renderer process has been compromised via secondary exploit chains.\nThe attack vector necessitates that an attacker first achieve arbitrary code execution within the Chrome renderer process. Once the renderer process is compromised, the attacker must employ social engineering to convince a user to interact with a specifically crafted HTML page. This page contains malicious JavaScript designed to interact with the vulnerable Bluetooth interface. Because the renderer process lacks the necessary security constraints to validate the legitimacy of these Bluetooth requests, the browser fails to adequately isolate the request scope.\nUpon execution, the crafted HTML page triggers a sequence of Bluetooth API calls that exploit the lack of rigorous input sanitization or object validation in the Bluetooth handler. This allows the renderer process to query for or intercept sensitive information that is then transmitted back to the attacker's command-and-control server. The core technical failure is the breakdown of the privilege boundary between the low-privilege renderer process and the higher-privilege browser process responsible for hardware communication. The browser fails to enforce strict origin-based or capability-based security checks during the Bluetooth handshake process, permitting the exfiltration of data that would otherwise be shielded by the browser's sandbox. The impact is primarily categorized as an information disclosure, wherein the attacker can retrieve device-specific identifiers, connectivity state, or potentially other sensitive Bluetooth metadata, depending on the scope of the exposure permitted by the operating system's driver interaction. Successful exploitation does not grant full control over the host system but bypasses essential browser-level privacy protections."
}
CVE-2026-79001: Chrome Bluetooth Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere