Description
Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via crafted Chrome extension
Action: Patch immediately
AI Analysis

Impact

Google Chrome implements Regional Capabilities that control what a browser can access on the system. The CVE exposes improper privilege management in those capabilities, so a crafted Chrome extension can bypass the intended restrictions. An attacker who convinces a user to install a malicious extension can therefore gain privileges that exceed the browser’s normal sandbox, potentially allowing broader system access.

Affected Systems

All installations of Google Chrome on any supported operating system with versions earlier than 152.0.7977.65 are affected. The issue pertains to the desktop channel of Chrome where the older Regional Capabilities implementation was used.

Risk and Exploitability

The Chromium severity assessment rates the issue as Medium, but the CVSS score of 8.8 classifies it as high severity. No public exploit is documented as of the latest advisories. The EPSS score indicates a very low exploitation probability (< 1%). The vulnerability is not listed in the KEV catalog. The risk remains moderate due to the requirement for social engineering to install the malicious extension, although the potential impact is high once the extension is installed.

Generated by OpenCVE AI on August 28, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later
  • Disable or remove any unexplained or untrusted Chrome extensions
  • Configure the browser or organizational policy to block installation of extensions from unknown sources and educate users about the risks of social‑engineering attacks

Generated by OpenCVE AI on August 28, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension Privilege Escalation via Regional Capability Mismanagement

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension Privilege Escalation via Regional Capability Mismanagement

Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
Weaknesses CWE-269
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T19:06:28.970Z

Reserved: 2026-08-25T06:12:01.222Z

Link: CVE-2026-79226

cve-icon Vulnrichment

Updated: 2026-08-28T19:05:30.942Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:16.743

Modified: 2026-08-31T14:04:31.830

Link: CVE-2026-79226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:00:14Z

Weaknesses
  • CWE-269

    Improper Privilege Management