Impact
The defect is a protection mechanism failure in the HttpsUpgrades component of Google Chrome prior to version 152.0.7977.65. A remote attacker can send specially crafted network traffic that makes the browser treat a non‑HTTPS source as if it were a different origin, thus bypassing the browser's same‑origin policy. This weakness, classified as CWE‑693, can lead to theft of privileged data or execution of malicious code under the guise of a trusted origin.
Affected Systems
Google Chrome browsers with versions earlier than 152.0.7977.65 are affected. Systems running the stable channel released before the August 2026 update are at risk.
Risk and Exploitability
The CVSS score is 4.3, indicating medium severity, while the EPSS score is <1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Triggering the flaw requires crafted network traffic that can be sent without user interaction over an open network. As a result, remote attackers could potentially use automated or remote campaigns to exploit this origin‑policy bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA