Sceawere

Vulnerability Detail

CVE-2026-79133UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Forms Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Incorrect authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-25T21:18:08.600Z",
  "pubdate": "2026-08-25T21:18:08.600Z",
  "executiveSummary": "A security vulnerability categorized as incorrect authorization exists within the Forms component of Google Chrome prior to version 152.0.7977.65.\nThe flaw allows a remote attacker to circumvent authorization controls, leading to the unauthorized disclosure of sensitive information.\nThe vulnerability is triggered by a crafted HTML page, which does not require authentication or elevated user privileges to execute.\nThis issue exposes users to potential data exfiltration of information processed or stored within the browser's form handling mechanisms.\nGiven the nature of the flaw, a remote attacker can exploit this via web-based vectors, impacting the confidentiality of user data.\nThe Chromium project has classified the security severity of this vulnerability as Low.",
  "technicalDetails": "The root cause of this vulnerability lies in an incorrect authorization implementation within the Chrome Forms handling component. Specifically, the browser fails to properly enforce security policies or access control checks when processing form-related data structures initiated or interacted with by a crafted HTML page.\nWhen a user navigates to an attacker-controlled web page, the malicious HTML can interact with the browser's Forms component. Due to the insufficient authorization checks, the browser inadvertently exposes sensitive data that should otherwise be protected by the Same-Origin Policy (SOP) or other internal browser security boundaries.\nThe attack flow follows a structured path: First, an attacker hosts a specially crafted HTML page designed to leverage the flaw in the Forms component. Second, the attacker lures a target user to visit this page. Third, upon rendering, the malicious code executes, triggering the improper authorization flow within the Forms subsystem. Finally, the browser returns sensitive information to the attacker's script, bypassing intended security restrictions.\nThis vulnerability is classified as an incorrect authorization issue, rather than a traditional memory corruption bug. It involves logic errors in how the browser validates the context or origin of requests made to the Forms component. The affected component is the internal Forms management architecture within Chromium, which is responsible for auto-filling, form submission, and related DOM-level interactions.\nThe vulnerability affects Google Chrome versions prior to 152.0.7977.65. Successful exploitation occurs without requiring user authentication, and the attacker does not need to possess pre-existing privileges on the host system. The network exposure is broad, as the attack is delivered over standard web protocols (HTTP/HTTPS) when the user interacts with the malicious content.\nPost-exploitation, the impact is primarily the loss of confidentiality. The attacker may gain unauthorized access to data that the user intended to keep private or data that is contextually tied to the user's interaction with forms. Since the browser manages sensitive user inputs, the scope of the exfiltrated information could include personal identifiable information (PII), session-related data, or cached form input history."
}
CVE-2026-79133: Google Chrome Forms Authorization Bypass (MEDIUM Severity, CVSS: 6.5) - Sceawere