SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79148

CRITICAL · CVSS 9.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An off-by-one error in the DevTools component of Google Chrome versions prior to 152.0.7977.65 allows remote attackers to exploit this vulnerability through social engineering tactics, potentially enabling them to read sensitive memory data within the sandbox environment via a specially crafted Chrome extension. While the Chromium security team has classified the severity as low, organizations using affected versions of Chrome should prioritize updates to mitigate the risk of exploitation.

CVE
CVE-2026-79148
Severity
CRITICAL
CVSS
9.1
EPSS
0.26%
Chrome

Original NVD Description

Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

Related CVEs

Other vulnerabilities affecting the same vendor(s)