Description
Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypasses web origin policy enabling unauthorized same‑origin access
Action: Apply Patch
AI Analysis

Impact

Chrome’s Loader incorrectly resolves references in versions prior to 152.0.7977.65, allowing a remote attacker to craft network traffic that tricks the browser into treating a resource as same‑origin. The description indicates a bypass of the web origin policy; it is inferred that this could enable the attacker to access data or execute scripts within the victim’s origin context, though those specific outcomes are not explicitly documented.

Affected Systems

The vulnerability is present in Google Chrome desktop releases older than 152.0.7977.65 on all supported operating systems; no other vendors or products are listed as affected.

Risk and Exploitability

The EPSS score of less than 1 % and the fact that the vulnerability is not listed in CISA’s KEV catalog imply a low probability of active exploitation. The CVSS score of 4.3 classifies it as medium severity, indicating that the flaw can lead to a partial compromise of web origin integrity but does not enable broad remote code execution. Exploitation requires only crafted network traffic that tricks the Loader into resolving a reference as same‑origin, and does not depend on user interaction or local privilege escalation. Consequently, while an attacker might gain unauthorized access to resources marked as same‑origin, the overall impact is limited compared to high‑severity vulnerabilities. Prompt patching and monitoring of anomalous origin resolution attempts continue to be the primary defense.

Generated by OpenCVE AI on August 28, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later on all affected installations
  • Implement content security policies that enforce strict same‑origin policies and validate origin handling of network responses
  • Monitor browser logs and network traffic for abnormal origin resolution patterns that may indicate exploitation attempts

Generated by OpenCVE AI on August 28, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome Loader Reference Resolution Vulnerability Bypasses Web Origin Policy

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Chrome Loader Reference Resolution Vulnerability Bypasses Web Origin Policy

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:36:35.467Z

Reserved: 2026-08-25T06:04:20.578Z

Link: CVE-2026-78942

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:50.073

Modified: 2026-08-28T17:32:25.287

Link: CVE-2026-78942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:15:05Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference