6.5
CVE-2026-79076
- EPSS 0.31%
- Veröffentlicht 25.08.2026 20:10:12
- Zuletzt bearbeitet 31.08.2026 13:38:16
- Erkennungen
Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.23 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
https://issues.chromium.org/issues/496395158