Description
Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits a remote attacker to leak sensitive cross‑origin data through the StorageAccessAPI in Google Chrome. By delivering a crafted HTML page, an attacker can obtain information that the browser would normally keep segregated. This is an information‑disclosure flaw classified as CWE‑200. The exploit would not modify or destroy data, but it violates user confidentiality and can expose private information.

Affected Systems

Google Chrome browsers prior to version 152.0.7977.65 are affected. Users running any earlier stable channel version could be exposed to the data leak.

Risk and Exploitability

The exploit can be carried out remotely by hosting a malicious HTML page that a victim visits. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation at this time. The Chromium severity is marked low, and the CVSS score reflects a low impact. Nevertheless, the data exposed can be valuable, so the risk is low to moderate depending on the confidentiality of the compromised data.

Generated by OpenCVE AI on August 25, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later. This patch removes the StorageAccessAPI vulnerability.
  • Configure Chrome policies or site settings to block or limit StorageAccessAPI usage for untrusted origins, ensuring cross‑origin storage requests are denied.
  • Implement network or CSP‑based monitoring to detect and block unnecessary cross‑origin data transfers from malicious pages.

Generated by OpenCVE AI on August 25, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via StorageAccessAPI in Google Chrome

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-25T20:10:53.094Z

Reserved: 2026-08-25T06:03:54.241Z

Link: CVE-2026-78896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:46.963

Modified: 2026-08-25T21:17:46.963

Link: CVE-2026-78896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor