Description
Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Origin policy bypass via renderer compromise
Action: Update Chrome
AI Analysis

Impact

The vulnerability exists in the Chrome Network module where a missing authorization check allows a compromised renderer process to request network resources that bypass the browser’s same‑origin policy. This flaw is identified as CWE-862 and is rated Medium severity by Chromium security. By serving a specially crafted HTML page, an attacker can cause the renderer to access cross‑origin data, potentially exfiltrating confidential information or injecting malicious content.

Affected Systems

All installations of Google Chrome on desktop platforms running a stable‑channel version older than 152.0.7977.65 are affected. This includes Windows, macOS, and Linux environments, and the issue is not tied to any specific operating system.

Risk and Exploitability

The attack requires a prior compromise of the renderer process, so the privilege level of the attacker must be high; this inference is based on the description of the vulnerability. The CVSS score is 4.3 and the EPSS score is < 1%, indicating a Medium severity rating and suggesting a moderate risk. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are currently documented. Updating Chrome promptly is the recommended remediation to restore proper authorization checks and prevent the bypass.

Generated by OpenCVE AI on August 28, 2026 at 18:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer to restore the missing authorization check.
  • If an upgrade cannot be performed immediately, disable renderer network access or disable remote debugging features that enable a compromised renderer to communicate with the network component.
  • Enable Chrome’s site isolation and configure automatic updates or proactively monitor the stable channel release notes for forthcoming security patches.

Generated by OpenCVE AI on August 28, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Authorization Bypass Allows Origin Policy Circumvention in Google Chrome

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:06.707Z

Reserved: 2026-08-25T06:08:56.778Z

Link: CVE-2026-79085

cve-icon Vulnrichment

Updated: 2026-08-27T20:31:50.316Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:04.087

Modified: 2026-08-28T17:30:57.780

Link: CVE-2026-79085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses