Description
Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An input validation flaw in Google Chrome’s Sync component allows a remote attacker to supply specially crafted network traffic, which can lead to the disclosure of sensitive information. The flaw exists in Chrome versions prior to 152.0.7977.65 and is classified as a medium‑severity issue by Chromium developers.

Affected Systems

Based on the description, it is inferred that all desktop users running Google Chrome releases before 152.0.7977.65 with Sync enabled are affected. The issue pertains to the Sync component handling cloud‑stored data synchronization.

Risk and Exploitability

The vulnerability permits a remote attacker to send specially crafted network traffic to Chrome’s Sync component, potentially exposing sensitive data. The description does not specify whether authentication is required, so it is unclear if the attacker needs valid Chrome credentials or can target any user with Sync enabled. The CVSS score of 6.5 reflects a medium severity, the EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Overall, the risk is moderate and primarily threatens the confidentiality of information stored in Sync.

Generated by OpenCVE AI on August 26, 2026 at 22:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or later on all affected systems
  • Verify that Chrome’s auto‑update feature is enabled to receive future security patches automatically
  • If an upgrade cannot be performed immediately, disable Sync until a patched version is available to limit data exposure

Generated by OpenCVE AI on August 26, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Sync Enables Remote Sensitive Data Exposure

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Sync Enables Remote Sensitive Data Exposure

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:45:40.730Z

Reserved: 2026-08-25T06:08:40.223Z

Link: CVE-2026-79076

cve-icon Vulnrichment

Updated: 2026-08-26T18:09:18.290Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:03.390

Modified: 2026-08-31T13:38:16.100

Link: CVE-2026-79076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:00:14Z

Weaknesses
  • CWE-20

    Improper Input Validation