Description
Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Origin policy bypass enabling cross‑origin data access
Action: Patch immediately
AI Analysis

Impact

A flaw in Google Chrome’s QUIC implementation before version 152.0.7977.65 allows a remote attacker to craft an HTML page that causes the browser to treat resources from a different origin as if they were from the same origin. This arbitrarily relaxes the same‑origin policy and can expose sensitive data or allow session hijacking, taking advantage of the CWE‑610 weakness.

Affected Systems

The vulnerability applies to Google Chrome browsers earlier than 152.0.7977.65. All users running that version are susceptible regardless of operating system.

Risk and Exploitability

Chromium rates this issue as Medium severity. The CVSS score is 4.3, indicating moderate impact. The EPSS score is <1%, implying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it by delivering a crafted HTML page over the internet; the attack requires user interaction but imposes no additional infrastructure. Given the moderate severity and low exploitation probability, the risk is moderate but still significant due to potential widespread data exposure.

Generated by OpenCVE AI on August 28, 2026 at 19:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to 152.0.7977.65 or later where the QUIC reference bug is fixed
  • If an update is delayed, disable QUIC by turning off the "Experimental QUIC protocol" flag in Chrome settings or launching Chrome with the "--disable-quic" command‑line option
  • Consider blocking QUIC traffic at the network level to prevent the protocol from being used until the browser is updated

Generated by OpenCVE AI on August 28, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Externally Controlled Reference in QUIC Allows Origin Policy Bypass via Crafted Page

Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Externally Controlled Reference in QUIC Allows Origin Policy Bypass via Crafted Page
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-610
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:07.767Z

Reserved: 2026-08-25T06:05:19.495Z

Link: CVE-2026-78966

cve-icon Vulnrichment

Updated: 2026-08-27T20:32:14.514Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:52.730

Modified: 2026-08-28T14:20:34.963

Link: CVE-2026-78966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:15:05Z

Weaknesses
  • CWE-610

    Externally Controlled Reference to a Resource in Another Sphere