Description
Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from incorrect reference resolution in the Cache component of Google Chrome before version 152.0.7977.65. A remote attacker can serve a crafted HTML page that causes the browser to misinterpret references, enabling the attacker to bypass the browser’s web origin policy. This flaw allows the attacker to access resources or perform actions that should be restricted by origin boundaries, potentially compromising user data or allowing further malicious activity.

Affected Systems

All users running Google Chrome with a version earlier than 152.0.7977.65 are affected. The issue is specific to the Chrome desktop stable channel; newer releases receive the fix within the same update cycle.

Risk and Exploitability

The flaw can be exploited remotely through a malicious web page. The EPSS score indicates a very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. While the Chromium project rates the severity as Medium, corresponding to a CVSS score of 4.3, the ability to break origin isolation poses a significant threat to confidentiality and integrity of user data if the attacker can deliver the crafted page. The attack vector relies on network delivery of manipulated content, so hosting or injecting content into a trusted site would likely be required.

Generated by OpenCVE AI on August 28, 2026 at 18:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later via the automatic update system
  • Enable and maintain automatic updates to receive security patches promptly
  • Avoid opening untrusted or suspicious web pages until the update has been applied

Generated by OpenCVE AI on August 28, 2026 at 18:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chrome Cache Reference Resolution Bypass of Web Origin Policy

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chrome Cache Reference Resolution Bypass of Web Origin Policy

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:36:34.002Z

Reserved: 2026-08-25T06:08:33.363Z

Link: CVE-2026-79070

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:02.697

Modified: 2026-08-31T16:38:49.567

Link: CVE-2026-79070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:30:08Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference