Sceawere

Vulnerability Detail

CVE-2026-79023UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Incorrect Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Incorrect authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-25T21:17:58.210Z",
  "pubdate": "2026-08-25T21:17:58.210Z",
  "executiveSummary": "This vulnerability involves an incorrect authorization flaw within the Editing component of Google Chrome, affecting versions prior to 152.0.7977.65.\nThe security defect permits a remote, unauthenticated attacker to bypass established security boundaries to exfiltrate sensitive information from the user's browser environment.\nThe vulnerability is triggered when a victim interacts with a specifically crafted HTML page designed to exploit the logic errors in the browser's editing authorization routines.\nCategorized with a Chromium security severity of Medium, this flaw presents a notable risk to user data confidentiality.\nSuccessful exploitation allows for unauthorized access to information that should otherwise be protected by the browser's origin-based security model.\nThe exploitation does not require advanced persistent privileges on the host system, but rather relies on the victim's interaction with malicious web content, making it a viable vector for drive-by information harvesting.",
  "technicalDetails": "The vulnerability resides within the Editing subsystem of the Chromium engine, which handles rich text operations, clipboard interactions, and content manipulation. The root cause is an incorrect authorization check during the execution of editing-related functions. In a secure state, these operations must strictly adhere to the Same-Origin Policy (SOP) and internal permission models to prevent unauthorized scripts from reading or modifying protected content across different browsing contexts.\nThe flaw manifests when the browser's internal authorization logic fails to properly validate the context or the source origin before performing sensitive editing operations. Because the authorization verification is bypassed, the browser incorrectly assumes that the requesting script has the necessary permissions to access, process, or expose data that resides within the scope of the Editing component. This essentially collapses the security boundary that isolates data from potentially malicious web origins.\nThe attack flow initiates when a remote attacker hosts a crafted HTML page containing malicious scripts designed to target specific Editing APIs. When a user navigates to this page, the script executes within the renderer process. The payload leverages the compromised Editing subsystem to perform unauthorized read operations. By manipulating the browser's state through these legitimate but improperly authorized APIs, the attacker can extract sensitive information. This data exfiltration could include, but is not limited to, clipboard contents, active document fragments, or other data managed by the editing engine that is not intended for public access.\nThe vulnerability affects all Google Chrome versions prior to 152.0.7977.65. Exploitation does not require the attacker to have pre-existing authentication or elevated local privileges on the victim's machine. The attack is network-exposed, requiring only that the victim visits a malicious site or a site hosting malicious advertisements or injected content. Post-exploitation, the attacker gains the ability to exfiltrate sensitive data directly to a remote server, potentially compromising user privacy, session tokens, or other sensitive user-input data handled by the editing interface."
}
CVE-2026-79023: Google Chrome Incorrect Authorization Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere