Description
Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Apply Patch
AI Analysis

Impact

A bug in Chrome’s StorageAccessAPI performs an incorrect authorization check, letting a remote attacker who has already compromised the renderer process bypass the web origin policy. By serving a specially crafted HTML page, the attacker can read or manipulate storage for origins that should remain isolated, potentially exposing sensitive data. The Chrome security team rated the issue as low severity.

Affected Systems

Google Chrome versions earlier than 152.0.7977.65 are affected. The security fix is delivered through the stable channel update referenced in the Chrome release blog.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium risk, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so the risk assessment is based solely on the vendor’s low severity rating. Exploitation requires control of a renderer process that can serve a crafted page, limiting the attack surface to compromised renderer contexts only.

Generated by OpenCVE AI on August 26, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or newer to receive the StorageAccessAPI authorization fix.
  • Ensure automatic download and installation of Chrome updates is enabled on the system so the patch is applied promptly.
  • Restrict loading of untrusted web content and consider enabling safe browsing features or disabling third‑party extensions that inject arbitrary HTML to reduce chances of renderer compromise.

Generated by OpenCVE AI on August 26, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome StorageAccessAPI Origin Policy Bypass via Renderer Compromise

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome StorageAccessAPI Origin Policy Bypass via Renderer Compromise

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:19:38.536Z

Reserved: 2026-08-25T06:07:10.262Z

Link: CVE-2026-79005

cve-icon Vulnrichment

Updated: 2026-08-26T19:19:35.081Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:56.207

Modified: 2026-08-27T17:51:06.730

Link: CVE-2026-79005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses