Description
Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in ReaderMode allows a remote attacker to bypass the web origin policy and access a privileged page through a crafted HTML page. The flaw could enable the attacker to execute privileged actions in the context of that page. The vulnerability is based on CWE-20 and is classified as low severity by Chromium security teams.

Affected Systems

Google Chrome browsers with versions earlier than 152.0.7977.65 are affected. The ReaderMode feature is the specific component impacted.

Risk and Exploitability

The CVSS score is not disclosed, the EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. The attack requires a social‑engineering vector where the user opens or interacts with a malicious HTML page that triggers ReaderMode. Once the page is loaded, the origin policy is bypassed, allowing the attacker to access privileged resources within that context.

Generated by OpenCVE AI on August 25, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later
  • Configure browsers to apply automatic updates to ensure the fix is installed promptly
  • Educate users to avoid opening unsolicited or suspicious HTML links that could trigger ReaderMode exploitation

Generated by OpenCVE AI on August 25, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Web Origin Policy Bypass via ReaderMode Input Validation Flaw
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-25T20:10:55.151Z

Reserved: 2026-08-25T06:06:36.765Z

Link: CVE-2026-78980

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:54.427

Modified: 2026-08-25T21:17:54.427

Link: CVE-2026-78980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation