Description
Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Origin Policy Bypass
Action: Immediate Patch
AI Analysis

Impact

A flaw in the StreamsAPI of Google Chrome allows a crafted web page to expose privileged resources to scripts that normally would not have access. The vulnerability can be used by a remote attacker to bypass the web origin policy and reach privileged pages. The weakness is an improper exposure of protected resources, which could lead to information disclosure or unauthorized actions on behalf of the user.

Affected Systems

All users running Google Chrome versions earlier than 152.0.7977.65 are affected. The flaw resides in the StreamsAPI layer used by the browser to manage data streams, and only the listed Chrome builds contain the unpatched implementation.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3, indicating a medium severity risk, with an EPSS score of less than 1% and is not listed in the CISA KEV catalog. An attacker can exploit it by serving a specially crafted HTML file that triggers the vulnerable StreamsAPI, thereby bypassing origin restrictions. Because the attack vector is a web page loaded over the network, remote exploitation is feasible without local privileges.

Generated by OpenCVE AI on August 28, 2026 at 18:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to 152.0.7977.65 or later, which contains the StreamsAPI fix.
  • If an update cannot be applied immediately, disable or restrict the StreamsAPI via Chrome policy settings or the --disable-remote-streams flag to prevent the resource exposure.
  • Apply a strong content security policy that limits script origins and blocks access to privileged pages from untrusted content.

Generated by OpenCVE AI on August 28, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title StreamsAPI Resource Exposure Allows Origin Policy Bypass in Chrome

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title StreamsAPI Resource Exposure Allows Origin Policy Bypass in Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-668
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:07.018Z

Reserved: 2026-08-25T06:08:31.347Z

Link: CVE-2026-79068

cve-icon Vulnrichment

Updated: 2026-08-27T20:31:56.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:02.477

Modified: 2026-08-31T16:37:39.590

Link: CVE-2026-79068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere