Description
Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: System Access Bypass via Crafted File
Action: Update Browser
AI Analysis

Impact

The vulnerability stems from incorrect reference resolution in the Passwords module of Google Chrome before version 152.0.7977.65. It allows a remote attacker to create a crafted file that, when processed by the browser, resolves references incorrectly and bypasses system access restrictions. This flaw could grant an attacker unauthorized access to local system resources and is classified as CWE-706 (Incorrect Authorization).

Affected Systems

Google Chrome browsers on any platform where Chrome is installed and running a version earlier than 152.0.7977.65 are affected. The issue resides in the Passwords feature and impacts systems that store or retrieve passwords through Chrome.

Risk and Exploitability

Chromium rates this issue as medium severity with a CVSS score of 4.3, the EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must deliver a crafted file to the user, who then opens or processes it; no additional interaction beyond file consumption is required. The risk is limited to environments where such files can be introduced, but the lack of exploitation data means the likelihood of real‑world attacks remains uncertain.

Generated by OpenCVE AI on August 28, 2026 at 23:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later to apply the reference resolution fix.
  • Disable the Passwords feature or password auto‑fill until the update is installed to reduce exposure.
  • Avoid opening untrusted files and consider using anti‑malware scanning to detect crafted files before they are processed by Chrome.

Generated by OpenCVE AI on August 28, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 29 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Reference Resolution Bug in Chrome Passwords Enables System Access Bypass via Crafted File

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Reference Resolution Bug in Chrome Passwords Enables System Access Bypass via Crafted File

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T19:06:07.674Z

Reserved: 2026-08-25T06:08:16.688Z

Link: CVE-2026-79049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:00.700

Modified: 2026-08-31T16:38:54.900

Link: CVE-2026-79049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:45:03Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference