Impact
Improper initialization in the Network component of Google Chrome allows a crafted HTML page to bypass the browser’s same‑origin policy. The flaw originates from incomplete or incorrect construction of data structures during startup, which in turn lets a remote attacker load content from a different origin without the usual security restrictions. This can lead to disclosure or alteration of data that the attacker should not be able to access, potentially compromising confidentiality and integrity of web transactions.
Affected Systems
Google Chrome browsers that are running any version earlier than 152.0.7977.65 are affected. Users of stable channel versions released before the August 2026 update that contains the fix fall into this category.
Risk and Exploitability
Chromium rates this issue as medium severity, providing it with a CVSS score of 4.3 and an EPSS score of less than 1%. The vulnerability is not listed in CISA KEV. The most likely attack vector is remote: a user who visits or interacts with a malicious web page can trigger the exploit without requiring elevated privileges or any additional software.
OpenCVE Enrichment
Debian DLA
Debian DSA