Description
Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Browser
AI Analysis

Impact

An authentication flaw in Chrome’s Device feature allows a remote attacker, through a crafted HTML page, to bypass system access restrictions. By exploiting incorrect authorization checks (CWE-863), a malicious HTML page can be served to a user, enabling unauthorized access to device capabilities that should be protected within the browser. The effect is an escalation of privileges from a normal user to a higher level of system resource access.

Affected Systems

Google Chrome browsers running versions prior to 152.0.7977.65 are vulnerable. The issue affects the stable channel of Chrome on all supported operating systems until the stated fixed version is installed.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3, rated as Medium severity, and is not listed in the CISA KEV catalog. Exploitation requires social engineering of the victim to load the malicious HTML, indicating that proactive user awareness and prompt updates are key defenses. While an attacker cannot achieve arbitrary code execution, the ability to lift system access restrictions poses a significant risk for targeted users. The EPSS score of < 1% indicates a very low probability of exploitation.

Generated by OpenCVE AI on August 29, 2026 at 00:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later on all affected machines.
  • If an upgrade cannot be applied immediately, disable the Device feature using Chrome policies or settings so that untrusted HTML pages cannot access device capabilities.
  • Educate users about phishing and social engineering risks, ensuring they do not open unfamiliar HTML files from unknown sources.

Generated by OpenCVE AI on August 29, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Crafted HTML Page in Chrome Device Feature

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Crafted HTML Page in Chrome Device Feature

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:46:00.110Z

Reserved: 2026-08-25T06:07:08.354Z

Link: CVE-2026-79003

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:55.977

Modified: 2026-08-31T13:39:43.707

Link: CVE-2026-79003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses