Sceawere
Vulnerability Detail
CVE-2026-79181UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Glic Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 1d ago
- Vendor
- Product
- Chrome
- Attack Type
- Observable discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-25T21:18:11.710Z",
"pubdate": "2026-08-25T21:18:11.710Z",
"executiveSummary": "This vulnerability involves an observable discrepancy within the Glic component of Google Chrome, which could allow a remote attacker to exfiltrate sensitive information.\nThe flaw is classified as an information disclosure issue, occurring when the application leaks internal states or data through unintended variations in its processing logic.\nThe affected product is Google Chrome, specifically versions prior to 152.0.7977.65.\nThe risk implication is that an attacker, by utilizing a specifically crafted HTML page, can bypass standard security boundaries to gain unauthorized access to data that should otherwise remain isolated.\nExploitation requires no user authentication, though it necessitates that a user visits a malicious or compromised web page, leveraging the browser's rendering engine to trigger the discrepancy.\nThe severity is officially rated as Low by the Chromium project, suggesting that while the impact is significant, the exploitability conditions are non-trivial or the data exposed is limited in scope.",
"technicalDetails": "The vulnerability resides within the Glic component of the Chromium browser architecture. An observable discrepancy occurs when the implementation of a specific process—in this case, data handling or state transition within Glic—manifests different behaviors based on input, allowing an observer to infer sensitive information through side-channel or logical observation.\nThe root cause is an inconsistency in how Glic manages or sanitizes information flows, leading to a state where the output varies in a manner that reveals underlying secrets or protected memory structures. In web browser security, such discrepancies often arise when complex rendering or background processes fail to maintain strict isolation or uniform timing across different input conditions.\nThe attack flow initiates when a remote attacker hosts a crafted HTML page containing malicious scripts or structured elements designed to interact with the Glic interface. When a target user navigates to this page, the browser's engine processes the crafted input, triggering the flawed logic within the Glic component. Because the component does not handle these specific inputs consistently, it inadvertently reveals sensitive information to the attacker's script.\nThe exploitation method relies on the attacker's ability to monitor the response or the side effects of the browser's interaction with the crafted HTML. By analyzing the discrepancy in the system's behavior, the attacker can piece together sensitive information—potentially including authentication tokens, session data, or other locally cached information accessible to the Glic subsystem.\nThe vulnerability affects all Google Chrome versions prior to 152.0.7977.65. There are no specific privilege requirements for the attacker, as the exploit is executed within the context of the browser's renderer process. Network exposure is inherent to any web-based content, meaning any user who can reach the attacker-controlled server is potentially at risk if they load the malicious content.\nPost-exploitation, the attacker may be able to exfiltrate the collected sensitive data to a remote server, facilitating further identity theft or unauthorized account access, depending on the specific nature of the data retrieved via the discrepancy."
}