Description
Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote data disclosure via incorrect authorization in getUserMedia
Action: Patch
AI Analysis

Impact

The vulnerability is an authorization flaw in Chrome’s getUserMedia API that allows a malicious webpage to request and collect camera or microphone data without the user’s explicit permission. Because the check is performed incorrectly, a remote attacker can trick the browser into providing sensitive media streams from a victim’s device. The flaw is classified as Chromium's medium severity, indicating a risk of confidential data exposure rather than code execution or system takeover.

Affected Systems

Google Chrome browsers running any stable channel release prior to 152.0.7977.65 are affected. Any user who has not upgraded to this version is potentially vulnerable to attack via a crafted HTML page served over the network.

Risk and Exploitability

The CVSS score is 6.5, indicating medium severity. The EPSS score is < 1%, showing a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via a web page that the user visits; the attacker does not need elevated privileges or local access. If unpatched, an attacker could use the exposed media stream to obtain confidential video or audio data, compromising privacy.

Generated by OpenCVE AI on August 26, 2026 at 21:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later to address the authorization check in getUserMedia
  • Restrict camera and microphone permissions in Chrome settings or use policies to limit access for untrusted origins
  • If an upgrade is pending, consider disabling or blocking getUserMedia entirely via extensions or enterprise policy

Generated by OpenCVE AI on August 26, 2026 at 21:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in GetUserMedia Allows Remote Data Disclosure in Google Chrome

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in GetUserMedia Allows Remote Data Disclosure in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:39:15.844Z

Reserved: 2026-08-25T06:10:12.939Z

Link: CVE-2026-79134

cve-icon Vulnrichment

Updated: 2026-08-26T18:16:56.361Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:08.717

Modified: 2026-08-31T16:53:31.897

Link: CVE-2026-79134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:15:04Z

Weaknesses