Description
Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-origin policy bypass
Action: Update Browser
AI Analysis

Impact

Improper initialization in the Network component of Google Chrome allows a crafted HTML page to bypass the browser’s same‑origin policy. The flaw originates from incomplete or incorrect construction of data structures during startup, which in turn lets a remote attacker load content from a different origin without the usual security restrictions. This can lead to disclosure or alteration of data that the attacker should not be able to access, potentially compromising confidentiality and integrity of web transactions.

Affected Systems

Google Chrome browsers that are running any version earlier than 152.0.7977.65 are affected. Users of stable channel versions released before the August 2026 update that contains the fix fall into this category.

Risk and Exploitability

Chromium rates this issue as medium severity, providing it with a CVSS score of 4.3 and an EPSS score of less than 1%. The vulnerability is not listed in CISA KEV. The most likely attack vector is remote: a user who visits or interacts with a malicious web page can trigger the exploit without requiring elevated privileges or any additional software.

Generated by OpenCVE AI on August 28, 2026 at 19:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer.
  • Configure enterprise policy to enforce strict same‑origin restrictions on the browser’s networking stack.
  • Educate users to keep their browsers updated and to avoid visiting suspicious or untrusted websites.

Generated by OpenCVE AI on August 28, 2026 at 19:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Improper Initialization Enables Cross-Origin Policy Bypass in Google Chrome

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Initialization Enables Cross-Origin Policy Bypass in Google Chrome

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-665
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:46:43.375Z

Reserved: 2026-08-25T06:04:18.849Z

Link: CVE-2026-78940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:49.833

Modified: 2026-08-28T17:32:31.610

Link: CVE-2026-78940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:45:03Z

Weaknesses