PatchSiren cyber security CVE debrief
CVE-2026-79089 Google CVE debrief
CVE-2026-79089 is a race condition vulnerability in Google Chrome's Transactions Platform on Android prior to version 152.0.7977.65. This vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page, requiring social engineering tactics. The CVE record was published on 2026-08-25T21:18:04.540Z and has not been modified since then. Defenders should be aware of the potential for social engineering attacks and prioritize patching Google Chrome on Android. The vulnerability has a CVSS score of 5.3 and is considered to have a medium severity. The attack vector involves leveraging social engineering to bypass system access restrictions.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-31
Who should care
Defenders responsible for Google Chrome on Android deployments, security teams focused on social engineering attacks, administrators of systems using Google Chrome on Android, and operators managing Android-based systems that utilize Google Chrome for browsing. These stakeholders should be aware of the potential for social engineering attacks and prioritize patching Google Chrome on Android to prevent exploitation.
Technical summary
CVE-2026-79089 is a race condition vulnerability in Google Chrome's Transactions Platform on Android. The vulnerability exists in versions prior to 152.0.7977.65 and can be exploited by a remote attacker via a crafted HTML page, requiring social engineering to bypass system access restrictions. The vulnerability has a CVSS score of 5.3 and is considered to have a medium severity. Defenders should prioritize patching Google Chrome on Android to prevent potential social engineering attacks.
Defensive priority
Defenders should prioritize patching Google Chrome on Android to prevent potential social engineering attacks.
Recommended defensive actions
- Patch Google Chrome on Android to version 152.0.7977.65 or later
- Implement social engineering defenses and user awareness programs
- Monitor for suspicious HTML page activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE-2026-79089 record indicates a race condition in Google Chrome's Transactions Platform on Android prior to version 152.0.7977.65. The vulnerability, with a CVSS score of 5.3, could allow a remote attacker to bypass system access restrictions via a crafted HTML page, requiring social engineering.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79089 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79089
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79089 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79089
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/513792983
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.