Chrome <152.0.7977.65 Passwords Missing Auth Spoof UI via Renderer
CVE-2026-79058 Published on August 25, 2026
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Vulnerability Analysis
CVE-2026-79058 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-79058 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-79058
Want to know whenever a new CVE is published for Google Chrome? stack.watch will email you.
Affected Versions
Google Chrome:- Version 152.0.7977.65 and below 152.0.7977.65 is affected.