Description
Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Update Chrome
AI Analysis

Impact

Google Chrome versions prior to 152.0.7977.65 on Windows store notification payloads with insufficient encryption strength. An attacker can exploit this weakness by hosting a crafted HTML page that, through social engineering, tricks a user into interacting with a notification. The crafted content then bypasses the browser’s web origin policy, allowing the attacker to read or manipulate data across origin boundaries. The vulnerability is classified as Medium severity by Chromium’s internal scoring system.

Affected Systems

Any Windows user running Google Chrome before version 152.0.7977.65 is affected. The issue specifically targets the notification subsystem of the Chrome browser.

Risk and Exploitability

The risk is elevated by the remote nature of the exploit and the reliance on user interaction, which is common in social engineering attacks. An EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low probability of exploitation, yet the vulnerability’s CVSS score of 4.3 places it in the Medium severity range, indicating that users who have not updated their browsers remain at risk. An attacker would likely deliver malicious HTML via email or a phishing site, and the lack of robust encryption in the notification channel removes a key defense against cross-origin data leakage.

Generated by OpenCVE AI on August 28, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later
  • Configure enterprise policy to disable or restrict notification usage for untrusted origins
  • Educate users on the risks of clicking unsolicited links and verify the authenticity of notification sources

Generated by OpenCVE AI on August 28, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Inadequate Encryption Strength in Chrome Notifications Allows Web Origin Policy Bypass

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Inadequate Encryption Strength in Chrome Notifications Allows Web Origin Policy Bypass

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-326
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:36:35.014Z

Reserved: 2026-08-25T06:08:56.115Z

Link: CVE-2026-79084

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:03.967

Modified: 2026-08-28T17:31:18.633

Link: CVE-2026-79084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:45:03Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength