Improper access control in Google Chromium - CVE-2026-79126
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass intended proxy functionality.
The vulnerability exists due to improper access control in Proxy when handling browser network operations. A remote attacker can induce the browser to use the proxy functionality in an unintended way to bypass intended proxy functionality.
User interaction is required to trigger the issue.
Affected software
Microsoft Edge
Google Chrome
Debian Linux
chromium (Debian package)
How to mitigate CVE-2026-79126
Microsoft Edge - update to 152.0.4191.53
Google Chrome - addressed in versions 151.0.7922.175, 152.0.7977.64
chromium (Debian package) - update to 152.0.7977.75-1~deb13u1