Description
Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Patch
AI Analysis

Impact

A flaw in the Glic handling code of Google Chrome, observable in versions prior to 152.0.7977.65, allows a remote attacker to cause a browser to expose sensitive information. The bug can be triggered from a crafted HTML page served over the network, and the Chromium team rated the internal security severity of the issue as low. The impact is strictly an information disclosure; it does not give the attacker code execution, privilege escalation, or denial of service capabilities.

Affected Systems

Google Chrome running on desktop platforms is affected, specifically any installation that has not reached version 152.0.7977.65 or newer. The issue is confined to the browser’s rendering engine and does not affect other Google services or operating system components.

Risk and Exploitability

The CVSS score for this vulnerability is 5.3, and its EPSS score is less than 1%; the vulnerability is not listed in the CISA KEV catalog. The attack requires the user to open a specially crafted web page, so it is a client‑side exploit that can be performed remotely. The Chromium stability score notes low severity, indicating that while the information leak is real, the overall risk to enterprise users is moderate and not likely to be widely exploited in the wild at this time.

Generated by OpenCVE AI on August 26, 2026 at 21:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest stable release (152.0.7977.65 or newer).
  • If an update is temporarily infeasible, configure Chrome to block or restrict loading of Glic‑based content via group policy or enterprise settings.
  • Monitor browser activity logs for abnormal page loads that might originate from untrusted web content and review for potential data leakage.

Generated by OpenCVE AI on August 26, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Glic Bug in Chrome Prior to 152.0.7977.65

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Glic Bug in Chrome Prior to 152.0.7977.65

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:36:50.840Z

Reserved: 2026-08-25T06:10:58.342Z

Link: CVE-2026-79181

cve-icon Vulnrichment

Updated: 2026-08-26T18:19:59.340Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:11.710

Modified: 2026-08-27T17:51:21.243

Link: CVE-2026-79181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses