Description
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-20
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker who has somehow compromised the renderer process to circumvent the web origin policy by crafting a malicious HTML page. The underlying weakness is an incorrect authorization check, classified as CWE‑863. By obtaining the ability to bypass the origin policy, the attacker could read or interact with resources on other origins that should be protected, effectively enabling unauthorized data access and potential further exploitation.

Affected Systems

Google Chrome versions prior to 151.0.7922.173 are affected. The issue may be present in any build of Chrome that does not incorporate the fix released in that update.

Risk and Exploitability

The CVSS score is 8.1, indicating high severity per Chromium’s security team. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires the attacker to first gain control of the renderer process and then persuade a user to load a crafted page, indicating that it probably needs user interaction and social engineering. Given the high impact of bypassing the origin policy, this represents a significant risk to applications and data accessed through Chrome.

Generated by OpenCVE AI on August 21, 2026 at 20:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome version 151.0.7922.173 or later, which contains the authorization fix for Workers.
  • Ensure that Chrome’s renderer process isolation and sandboxing settings are enabled to reduce the chance that a compromised renderer can affect other processes.
  • Educate users and administrators about social engineering tactics that could lead them to load malicious HTML content in Chrome, and encourage safe browsing practices.

Generated by OpenCVE AI on August 21, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4758-1 chromium security update
Debian DSA Debian DSA DSA-6476-1 chromium security update
History

Tue, 25 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Chrome Workers Allows Origin Policy Exfiltration

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Chrome Workers Allows Origin Policy Exfiltration

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 20 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-21T18:44:00.304Z

Reserved: 2026-08-18T19:28:09.462Z

Link: CVE-2026-76019

cve-icon Vulnrichment

Updated: 2026-08-21T18:43:43.711Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T21:17:10.040

Modified: 2026-08-25T16:37:23.093

Link: CVE-2026-76019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses