Description
Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized system access through renderer process exploitation
Action: Patch
AI Analysis

Impact

Missing authorization in the Network component of Google Chrome before 152.0.7977.65 allows a remote attacker who has compromised the renderer process to bypass system access restrictions by serving a specially crafted HTML page. This flaw can enable the attacker to read or modify files and data that normally would be protected by the operating system, effectively elevating privileges within the browser context. The Chromium severity is medium.

Affected Systems

All users running Google Chrome stable channel versions earlier than 152.0.7977.65 are affected. The issue is confined to the stable channel’s Network component and does not impact newer releases.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to moderate severity, while the EPSS score of < 1% suggests a low likelihood of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Exploitation requires an attacker to first compromise the renderer process—common attack vectors include drive‑by downloads or malicious extensions. Once the renderer is compromised, a crafted HTML page can bypass the Network component’s authorization checks and access protected system resources. Because the initial renderer compromise is required and no public exploits are known, the overall risk remains moderate.

Generated by OpenCVE AI on August 29, 2026 at 00:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer.
  • Disable or restrict extensions that load arbitrary web content to reduce the chance of renderer compromise.
  • Apply the Chrome sandboxing enhancements that isolate renderer processes and limit file system access.

Generated by OpenCVE AI on August 29, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Chrome Network Component Authorization Bypass via Renderer Process Compromise

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Component Authorization Bypass via Renderer Process Compromise

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T19:06:06.940Z

Reserved: 2026-08-25T06:08:30.199Z

Link: CVE-2026-79067

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:02.360

Modified: 2026-08-31T16:37:32.310

Link: CVE-2026-79067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses