Sceawere

Vulnerability Detail

CVE-2026-79126UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Proxy Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Incorrect provision of specified functionality
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-08-25T21:18:07.760Z",
  "pubdate": "2026-08-25T21:18:07.760Z",
  "executiveSummary": "This vulnerability involves an incorrect provision of functionality within the proxy implementation of Google Chrome on Windows.\nThe flaw allows an adjacent attacker to potentially exfiltrate sensitive information through the injection of crafted network traffic.\nAffecting Google Chrome versions prior to 152.0.7977.65, the vulnerability is categorized as Low severity by the Chromium project.\nThe attack requires the adversary to be in an adjacent network position relative to the victim, meaning they must reside on the same local network segment to intercept or inject traffic.\nExploitation does not require prior authentication or elevated privileges on the target system, leveraging the browser's internal handling of network proxies to bypass intended security boundaries.\nThe primary risk is the unauthorized disclosure of data traversing the proxy, which could include credentials, session tokens, or other sensitive information depending on the nature of the intercepted traffic.\nThe vulnerability underscores the necessity of strict validation of proxy-related configuration and traffic processing routines to prevent unauthorized data exposure.",
  "technicalDetails": "The vulnerability resides within the Proxy functionality of the Chromium engine as implemented in Google Chrome for Windows. The root cause pertains to an improper state or configuration handling during the proxy provision process, which fails to adequately sanitize or validate network traffic traversing the proxy stack.\nThe flaw is triggered when an attacker, positioned on the same adjacent network (Layer 2), sends crafted network packets to the victim's machine. Because the browser fails to correctly enforce restrictions on these proxy-related functions, the crafted traffic is incorrectly processed, causing the browser to disclose sensitive information that would otherwise be shielded from external parties.\nStep-by-step attack flow: 1. The attacker positions themselves on the same local subnet as the target running an affected version of Google Chrome (prior to 152.0.7977.65). 2. The attacker crafts specific network packets designed to interact with the target's proxy configuration or active proxy connections. 3. These packets are transmitted to the victim's host. 4. Upon reception, the Chromium proxy component fails to distinguish the malicious traffic as unauthorized or out-of-scope. 5. The application inadvertently processes the payload, resulting in the leakage of sensitive data—potentially including HTTP headers, cookies, or other metadata contained within the current network session—back to the attacker's machine.\nThis vulnerability highlights a critical failure in the boundary enforcement between the network layer and the browser's proxy management subsystem. Since the proxy acts as an intermediary for network requests, any flaw in its logic essentially compromises the confidentiality of all traffic flowing through it. In this instance, the flaw specifically pertains to how the browser handles unexpected inputs directed at proxy-related functionality, allowing an adjacent entity to trick the application into revealing data it should be protecting.\nThe impact is limited to the adjacent network scope, meaning the attacker cannot exploit this vulnerability remotely over the internet without being on the same local broadcast domain. However, in enterprise or shared network environments, this represents a viable vector for internal lateral movement and credential harvesting. Post-exploitation, the attacker may gain access to authenticated session data, allowing for further escalation or identity impersonation if the intercepted traffic includes sensitive session identifiers."
}
CVE-2026-79126: Google Chrome Proxy Information Disclosure (MEDIUM Severity, CVSS: 5.9) - Sceawere