Description
Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Update Browser
AI Analysis

Impact

The vulnerability is an improper input validation flaw in DeviceBoundSessionCredentials in Google Chrome. It enables a remote attacker who leverages social engineering to craft network traffic that bypasses the browser’s web origin policy. The flaw is associated with CWE‑20, which describes input validation failures that can lead to unauthorized security behavior.

Affected Systems

Affected products are Google Chrome browsers prior to version 152.0.7977.65 on all platforms. Users running any of the older Chrome releases are at risk. The issue was acknowledged in the Chromium issue tracker and addressed in the 152.0.7977.65 update.

Risk and Exploitability

The EPSS score is very low, below 1%, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 4.3 indicates low overall severity. The official severity assigned by Chromium is Low. However, because the flaw permits a remote attacker to bypass the web origin policy through crafted traffic, successful exploitation could potentially expose domain‑scoped web content or interact with device‑bound session credentials in ways not originally permitted. An attacker would need to convince a user to download or access malicious content to trigger the crafted traffic, making the threat primarily associated with social engineering.

Generated by OpenCVE AI on August 28, 2026 at 18:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later.
  • Ensure Chrome’s automatic update mechanism is enabled so future security patches are applied automatically.
  • Educate users not to engage with suspicious links or downloads that could trigger crafted network traffic, and be wary of social engineering attempts.

Generated by OpenCVE AI on August 28, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title DeviceBoundSessionCredentials Improper Validation Enabling Web Origin Policy Bypass

Fri, 28 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title DeviceBoundSessionCredentials Improper Validation Enabling Web Origin Policy Bypass

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:36:33.551Z

Reserved: 2026-08-25T06:07:05.359Z

Link: CVE-2026-79000

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:55.640

Modified: 2026-08-28T14:41:12.267

Link: CVE-2026-79000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation