Description
Missing authorization in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via UI Interaction. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure via unauthorized DevTools access, facilitating remote UI interaction
Action: Immediate Patch
AI Analysis

Impact

A missing authorization check in DevTools of Google Chrome prior to 152.0.7977.65 enables a remote attacker to obtain sensitive information through UI interaction. The vulnerability is classified as medium severity and allows only data disclosure, not execution or denial of service. It requires the attacker to convince a user to interact with the DevTools interface, typically through social engineering.

Affected Systems

The affected product is Google Chrome. Any Chrome installation older than version 152.0.7977.65 is vulnerable. No other vendors or products are listed.

Risk and Exploitability

The EPSS score is <1%, indicating a very low likelihood that this vulnerability is actively exploited in the wild. The CVSS score of 6.5 classifies it as Medium severity. It is not listed in the CISA KEV catalog, so no confirmed public exploitation is known. However, the lack of authorization in DevTools means that an attacker who successfully socially engineers a user can gather confidential information from the browser’s context. The risk is moderate, primarily tied to user interaction and potentially widespread in environments where sensitive data is rendered in Chrome. Prompt mitigation is advised to reduce the attack surface.

Generated by OpenCVE AI on August 26, 2026 at 21:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later to apply the authorization fix.
  • Disable or restrict DevTools access for users on sensitive systems using Chrome policy or command‑line flags.
  • Provide user education to mitigate the social‑engineering component of the attack.

Generated by OpenCVE AI on August 26, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Chrome DevTools Enables Remote UI Interaction Exploit

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Chrome DevTools Enables Remote UI Interaction Exploit
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via UI Interaction. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:39:31.846Z

Reserved: 2026-08-25T06:10:39.683Z

Link: CVE-2026-79154

cve-icon Vulnrichment

Updated: 2026-08-26T18:16:41.060Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:10.603

Modified: 2026-08-27T19:08:58.957

Link: CVE-2026-79154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:30:12Z

Weaknesses