Sceawere

Vulnerability Detail

CVE-2026-79122UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome SignIn Information Leak

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Information leak
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-08-25T21:18:07.320Z",
  "pubdate": "2026-08-25T21:18:07.320Z",
  "executiveSummary": "An information disclosure vulnerability has been identified within the SignIn component of Google Chrome. Affecting all versions of the browser prior to 152.0.7977.65, this security flaw is categorized with a Medium severity rating by the Chromium project. The vulnerability allows a remote, unauthenticated attacker to acquire sensitive data transmitted during authentication or synchronization processes. This compromise is achieved by transmitting specially crafted network traffic targeting the vulnerable client interface.\nThe primary risk implication of this flaw is the potential exposure of sensitive user credentials, session tokens, or account configuration details associated with the Google Chrome SignIn mechanism. Because the exploitation occurs over the network, attackers positioned on the path of communication (such as on a compromised local network or public Wi-Fi) or capable of generating malicious network responses could intercept or induce the leakage of this data. Successful exploitation undermines the confidentiality of the user's browser-to-cloud communications without requiring local access or elevated privileges on the victim's host machine. To minimize this risk, immediate deployment of updated browser versions is necessary to safeguard transport-level data and protect user session integrity.",
  "technicalDetails": "The security vulnerability resides within the SignIn component of Google Chrome, a core subsystem responsible for managing user authentication, profile synchronization, and session state transitions with Google's backend identity providers. In versions of the browser prior to 152.0.7977.65, this component fails to safely process certain network responses or network conditions, leading to an information leak.\nThe vulnerability is exposed to remote exploitation through the network vector. An attacker capable of observing, intercepting, or manipulating network traffic can execute this attack. When the Google Chrome SignIn component initiates authentication handshakes or synchronization requests, it expects strictly structured and secured data exchanges. However, because of insufficient validation or handling of network-level states and responses within the SignIn module, a remote attacker can transmit crafted network traffic to the client. This crafted traffic triggers an anomalous execution path or state in the browser's network-handling logic, resulting in the inadvertent exposure of sensitive data.\nThe attack flow follows a sequential progression. First, the victim user or the browser automatically initiates a network connection or transaction involving the Google Chrome SignIn component, such as syncing user profile data or logging into a Google account. Second, a remote attacker positioned to manipulate network responses intercepts the outbound requests or acts as a malicious endpoint responding to the browser's queries. Third, the attacker transmits crafted network traffic designed to exploit the boundary conditions or processing logic of the SignIn component. Fourth, upon receiving and processing this crafted network traffic, the vulnerable SignIn component behaves anomalously, leaking sensitive information over the network or in subsequent client responses, which the attacker then captures.\nExploitation of this vulnerability does not require local access, user interaction beyond normal browser operation, or elevated privileges, such as administrative or root rights, on the host machine. The attack vector is entirely network-based. The primary post-exploitation impact is a loss of confidentiality. The leaked information can include session identifiers, authentication tokens, or other sensitive user metadata processed by the SignIn system. If acquired, these assets can enable session hijacking, unauthorized profile synchronization, or downstream credential abuse across the user's Google services."
}
CVE-2026-79122: Chrome SignIn Information Leak (MEDIUM Severity, CVSS: 5.9) - Sceawere