Description
Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Remote Authorization Bypass
Action: Patch
AI Analysis

Impact

Missing authorization in the Lighthouse component of Google Chrome enabled a remote attacker who had already compromised the renderer process to bypass site isolation by serving a crafted HTML page. The vulnerability allows the attacker to access or manipulate data and resources across site boundaries, potentially compromising user confidentiality and integrity within the browser context.

Affected Systems

All desktop versions of Google Chrome released before 152.0.7977.65 were affected. The issue was addressed in the stable channel update for that release date.

Risk and Exploitability

Chromium rates this issue as low severity based on a CVSS score of 3.1. The EPSS score is < 1%, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires an initial compromise of the renderer process, often achieved through malicious content or social engineering. Once the renderer is compromised, the attacker can bypass site isolation and reach data from other sites. The risk is significant for environments relying on Chrome’s isolation features, but the likelihood of exploitation remains low due to the prerequisite of renderer compromise.

Generated by OpenCVE AI on August 28, 2026 at 18:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later.
  • Verify that Chrome’s site isolation settings remain enabled and are not overridden by extensions or policies.
  • Reboot the system to ensure fresh renderer processes are running updated code.

Generated by OpenCVE AI on August 28, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote Authorization Bypass in Google Chrome Lighthouse via Renderer Compromise

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote Authorization Bypass in Google Chrome Lighthouse via Renderer Compromise

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:07:00.211Z

Reserved: 2026-08-25T06:08:20.753Z

Link: CVE-2026-79053

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:01.143

Modified: 2026-08-31T16:37:24.743

Link: CVE-2026-79053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses