PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-79089 Google CVE debrief

CVE-2026-79089 is a race condition vulnerability in Google Chrome's Transactions Platform on Android prior to version 152.0.7977.65. This vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page, requiring social engineering tactics. The CVE record was published on 2026-08-25T21:18:04.540Z and has not been modified since then. Defenders should be aware of the potential for social engineering attacks and prioritize patching Google Chrome on Android. The vulnerability has a CVSS score of 5.3 and is considered to have a medium severity. The attack vector involves leveraging social engineering to bypass system access restrictions.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-08-31
Advisory published
2026-08-25
Advisory updated
2026-08-31

Who should care

Defenders responsible for Google Chrome on Android deployments, security teams focused on social engineering attacks, administrators of systems using Google Chrome on Android, and operators managing Android-based systems that utilize Google Chrome for browsing. These stakeholders should be aware of the potential for social engineering attacks and prioritize patching Google Chrome on Android to prevent exploitation.

Technical summary

CVE-2026-79089 is a race condition vulnerability in Google Chrome's Transactions Platform on Android. The vulnerability exists in versions prior to 152.0.7977.65 and can be exploited by a remote attacker via a crafted HTML page, requiring social engineering to bypass system access restrictions. The vulnerability has a CVSS score of 5.3 and is considered to have a medium severity. Defenders should prioritize patching Google Chrome on Android to prevent potential social engineering attacks.

Defensive priority

Defenders should prioritize patching Google Chrome on Android to prevent potential social engineering attacks.

Recommended defensive actions

  • Patch Google Chrome on Android to version 152.0.7977.65 or later
  • Implement social engineering defenses and user awareness programs
  • Monitor for suspicious HTML page activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE-2026-79089 record indicates a race condition in Google Chrome's Transactions Platform on Android prior to version 152.0.7977.65. The vulnerability, with a CVSS score of 5.3, could allow a remote attacker to bypass system access restrictions via a crafted HTML page, requiring social engineering.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-79089 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-79089

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-79089 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79089

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.