Multiple vulnerabilities in Google Chrome (August 26, 2026)
Multiple vulnerabilities have been discovered in Google Chrome. They allow an attacker to cause an unspecified security issue by the publisher.
CSIRTS triage
- What
- Multiple unspecified security issues in Google Chrome.
- Who is affected
- Chrome users.
- Urgency
- Moderate; specific impact unspecified by vendor; routine patching recommended.
- Action
- Update Google Chrome to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1081/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-790250.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790460.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790740.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790280.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790090.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790880.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790870.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-791370.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790060.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-789080.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple Vulnerabilitiescert-bund
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- mediumCVE-2026-79271: Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leve…nvd
- mediumCVE-2026-79265: Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote at…nvd
- highCVE-2026-79263: Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker…nvd
- mediumCVE-2026-79260: Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote …nvd
- unknownCVE-2026-79259: Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a re…nvd
- unknownCVE-2026-79258: Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote atta…nvd
- mediumCVE-2026-79249: Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker …nvd
- mediumCVE-2026-79246: Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote atta…nvd
- highCVE-2026-79245: Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had …nvd
- highCVE-2026-79230: Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a…nvd
Recent advisories for Google Chrome
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Google Chrome: Multiple Vulnerabilitiescert-bund · 2026-08-26
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-08-26
- mediumCVE-2026-79293: Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacke…nvd · 2026-08-25
- highCVE-2026-79292: Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attack…nvd · 2026-08-25
- mediumCVE-2026-79291: Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to o…nvd · 2026-08-25
- criticalCVE-2026-79290: Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ex…nvd · 2026-08-25
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Apache Tomcat (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in Veeam products (August 26, 2026)2026-08-26
- unknownVulnerability in Apereo CAS (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in SonicWall NetExtender (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in OpenSSL (August 26, 2026)2026-08-26