Sceawere

Vulnerability Detail

CVE-2026-79090UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Improper Privilege Management in Actor

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Improper privilege management
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-25T21:18:04.650Z",
  "pubdate": "2026-08-25T21:18:04.650Z",
  "executiveSummary": "This vulnerability involves an improper privilege management flaw within the Actor component of Google Chrome, identified in versions prior to 152.0.7977.65. The flaw permits a remote attacker to circumvent established system access restrictions. By employing social engineering techniques, an attacker can coerce a user into interacting with a specifically crafted HTML page, leading to unauthorized privilege escalation or restriction bypass.\nThe vulnerability is categorized as a privilege management issue, which poses a risk to the integrity of the browser's sandbox and system-level security boundaries. While the Chromium project classifies the severity as Low, the impact is significant for users relying on strict privilege isolation. The exploitation requires active user involvement, making social engineering the primary vector for attack. Successful exploitation does not require the attacker to have prior authentication; however, the browser's context must be reachable by the user. Mitigation is primarily achieved through upgrading the browser to the specified version or later, which includes the necessary patches to enforce stricter privilege controls within the Actor module.",
  "technicalDetails": "The root cause of the vulnerability lies in the Actor component within the Chromium architecture, where the management of privilege levels is insufficient during specific asynchronous operations. When the browser processes external content, the Actor component is responsible for maintaining the boundary between the renderer process and the underlying system resources. Improper validation or state tracking within this component allows for a logical race or state-confusion condition to be triggered via an attacker-controlled HTML page.\nThe attack flow initiates when an attacker distributes a crafted HTML page designed to deceive the user—typically via phishing or malicious advertisement redirection. Upon rendering this page, the attacker executes scripts that trigger an interaction with the vulnerable Actor interface. Because the Actor component fails to adequately verify the authorization context before performing restricted operations, the browser is induced to execute commands or access resources that should be prohibited based on the current privilege level.\nTechnically, the vulnerability manifests as a bypass of the security checks implemented to isolate web content from sensitive system hooks. When the malicious HTML page interacts with the Actor, it exploits a discrepancy in how privilege tokens are validated. This interaction does not inherently require a secondary memory corruption exploit, such as a heap buffer overflow; rather, it represents a logic flaw in the handling of internal actor messages. By crafting the sequence of browser events, an attacker can trick the system into granting the renderer process privileges that exceed the intended sandbox constraints.\nThe scope of this vulnerability is limited to Google Chrome versions prior to 152.0.7977.65. Exploitation remains contingent on the user's ability to navigate to the malicious site and execute the associated scripts. Once the restriction is bypassed, the impact includes the potential for elevated access to browser-scoped data, unauthorized interaction with system-integrated APIs, or further compromise of the local environment, depending on the breadth of the access granted to the Actor component during the specific incident."
}
CVE-2026-79090: Improper Privilege Management in Actor (CRITICAL Severity, CVSS: 9.8) - Sceawere