Description
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized System Access via Authorization Bypass
Action: Patch
AI Analysis

Impact

This flaw occurs in Google Chrome's network stack, where an incorrect authorization check allows a crafted HTML page to gain privileged access to system resources normally protected by the browser. When a user opens such a page, the browser may treat the content as if it has higher privileges, enabling the attacker to read or modify restricted data. The vulnerability is rated medium with a CVSS score of 4.3 and relates to CWE‑863 (Authorization Bypass through User-Controlled Input).

Affected Systems

Google Chrome desktop builds older than 152.0.7977.65 are affected. The issue resides in the network stack that validates user privileges during web content rendering, meaning any user running a vulnerable Chrome version on a desktop machine may be compromised if they visit a malicious HTML page.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation in the wild. With a CVSS score of 4.3, the flaw is considered medium severity. The likely attack vector is remote: the attacker must host a crafted HTML page and entice a victim to open it, which triggers the bypass during rendering.

Generated by OpenCVE AI on August 29, 2026 at 00:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (v152.0.7977.65 or later) to replace the flawed network authorization logic and enforce correct privilege checks, addressing the CWE‑863 issue.
  • If an update cannot be applied immediately, configure Chrome policies to block access to file:// URLs or disable privileged web APIs that allow system access, thereby neutralizing the flaw referenced by CWE‑863 for local HTML files.
  • Educate users to avoid opening unfamiliar HTML pages from untrusted sources and use Chrome's Safe Browsing features and reputable antivirus software to detect malicious content.

Generated by OpenCVE AI on August 29, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Chrome Network Stack via Crafted HTML

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Chrome Network Stack via Crafted HTML

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:46:00.438Z

Reserved: 2026-08-25T06:08:17.747Z

Link: CVE-2026-79050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:00.810

Modified: 2026-08-31T16:38:59.230

Link: CVE-2026-79050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses