Description
Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Apply update
AI Analysis

Impact

The vulnerability exists in Chrome's DataTransfer component, allowing a crafted HTML page to read sensitive information that should be protected. An attacker who can host or influence a page visited by a user could capture data that the browser should keep private, impacting confidentiality of that data. The weakness corresponds to information disclosure (CWE-200).

Affected Systems

Google Chrome browsers on desktop platforms with versions earlier than 152.0.7977.65 are affected. This includes all Chrome stable releases prior to the 152.0.7977.65 update.

Risk and Exploitability

The CVSS score of 6.5 reflects a medium severity, and the EPSS score is less than 1%, indicating a low likelihood of exploitation. The vulnerability is triggered by a maliciously crafted web page, giving an attacker a remote vector via the user's browser. No public exploits are known, and it is not listed in CISA's KEV catalog.

Generated by OpenCVE AI on August 26, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer, as released by Google.
  • Apply an enterprise policy that disables or restricts DataTransfer usage for untrusted sources.
  • Educate users to avoid or be cautious of sites that could serve maliciously crafted pages.

Generated by OpenCVE AI on August 26, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Information Leak via DataTransfer in Google Chrome

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Information Leak via DataTransfer in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:35:45.188Z

Reserved: 2026-08-25T06:12:29.501Z

Link: CVE-2026-79246

cve-icon Vulnrichment

Updated: 2026-08-26T18:21:42.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:19.000

Modified: 2026-08-28T14:35:05.190

Link: CVE-2026-79246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor