Description
Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

An observable discrepancy in Google Chrome's Performance APIs allows a remote attacker to read cross‑origin data from a crafted webpage. The flaw is identified as CWE‑203, meaning internal data is unintentionally revealed. The attacker could obtain sensitive metrics such as timestamps or navigation timings that belong to other origins, potentially exposing timing information that can aid further attacks.

Affected Systems

The vulnerability potentially affects any Google Chrome version that implements the affected Performance API before the fix is released. According to the description, all Chrome releases prior to version 152.0.7977.65 are vulnerable. Users should assume all older or unpatched Chrome installations are at risk until an official update resolves the discrepancy.

Risk and Exploitability

The issue can be triggered by uploading or visiting a malicious web page that the victim loads in Chrome, making the attack vector user‑directed and remote. The CVSS score of 6.5 indicates medium severity, and the EPSS score of < 1% suggests a low likelihood of exploitation in the near term. Although not listed in the CISA KEV catalog, the potential for cross‑origin data leakage warrants prompt action.

Generated by OpenCVE AI on August 28, 2026 at 23:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest stable release when Google publishes a new version, which resolves the Performance API discrepancy.
  • If an upgrade cannot be performed immediately, enforce an enterprise policy that blocks cross‑origin access to Performance APIs, utilizing Chrome’s policy settings.
  • Implement a content security policy that restricts the execution of third‑party scripts and inline code, reducing the ability of a crafted page to read performance data.

Generated by OpenCVE AI on August 28, 2026 at 23:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 29 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Performance API Discrepancy in Google Chrome

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Performance API Discrepancy in Google Chrome

Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T19:11:18.893Z

Reserved: 2026-08-25T06:05:02.739Z

Link: CVE-2026-78955

cve-icon Vulnrichment

Updated: 2026-08-28T19:10:40.754Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:51.520

Modified: 2026-08-31T18:58:41.910

Link: CVE-2026-78955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:45:03Z

Weaknesses