Description
Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch
AI Analysis

Impact

Chrome’s Sensor component has an authorization flaw that permits a remote attacker who has already compromised the renderer process to retrieve sensitive information by serving a specifically crafted HTML page. The vulnerability is classified as Medium severity by Chromium and maps to CWE-862, which concerns missing authorization.

Affected Systems

Google Chrome browsers running any version earlier than 152.0.7977.65 are affected; all later releases incorporate the fix.

Risk and Exploitability

The attack vector requires the attacker to already control the renderer process, meaning that the vulnerability is only exploitable after a prior compromise of the rendering environment. The CVSS score of 5.3 classifies the flaw as a Medium severity issue. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw allows data disclosure rather than system compromise, the overall risk is moderate, but the availability of a patch makes timely remediation important.

Generated by OpenCVE AI on August 26, 2026 at 22:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or newer.
  • Enable automatic updates to ensure future patches are applied without manual intervention.
  • Keep abreast of Google Chromium security advisories to apply any additional mitigations promptly.

Generated by OpenCVE AI on August 26, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Chrome Sensor Allows Sensitive Data Retrieval

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Chrome Sensor Allows Sensitive Data Retrieval

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:45:25.203Z

Reserved: 2026-08-25T06:09:25.161Z

Link: CVE-2026-79104

cve-icon Vulnrichment

Updated: 2026-08-26T18:09:38.015Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:05.667

Modified: 2026-08-28T14:38:13.690

Link: CVE-2026-79104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:30:04Z

Weaknesses