Description
Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch Chrome
AI Analysis

Impact

Observable differences in Chrome’s Network component before version 152.0.7977.65 allow a remote attacker to obtain sensitive data through a crafted HTML page. The flaw is classified as a medium‑severity information‑disclosure weakness, labeled CWE‑203, indicating that improper data handling can expose confidential material. The CVSS score of 5.3 confirms a medium severity level.

Affected Systems

Google Chrome Desktop versions earlier than 152.0.7977.65 are affected. The issue is observed in the desktop channel; based on the description, it is inferred that mobile or other variants are not impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity, and the EPSS score is < 1%, indicating low exploitation probability; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, requiring an attacker to host a maliciously crafted HTML page that a victim must load in the vulnerable browser. Once loaded, the network discrepancy can expose sensitive data. No active exploitation has been reported, so the risk is considered moderate until the patch is applied.

Generated by OpenCVE AI on August 27, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later, ensuring the build includes the network fix.
  • Verify that Chrome’s automatic update mechanism is enabled and that no enterprise policies disable updates; use the Chrome update settings or the Google Admin console if applicable.
  • If an update is unavailable, avoid using the affected Chrome version for sensitive activities and consider switching to an alternative browser until the patch is installed.

Generated by OpenCVE AI on August 27, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure in Chrome via Network Discrepancy

Thu, 27 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure in Chrome via Network Discrepancy

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T13:35:22.092Z

Reserved: 2026-08-25T06:07:51.275Z

Link: CVE-2026-79028

cve-icon Vulnrichment

Updated: 2026-08-26T18:38:59.643Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-25T21:17:58.803

Modified: 2026-08-27T17:20:45.707

Link: CVE-2026-79028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T16:00:15Z

Weaknesses