Description
Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation that allows an attacker to bypass system access restrictions
Action: Patch
AI Analysis

Impact

Improper privilege management in the Actor component of Google Chrome before version 152.0.7977.65 permits a remote attacker who uses social engineering to deliver a specially crafted HTML page to elevate privileges or bypass system access restrictions. The flaw is a CWE‑269 issue and does not provide arbitrary code execution. Rather, it can enable an attacker to manipulate the browser environment with higher authority than intended, potentially compromising user data confidentiality or integrity through unauthorized access.

Affected Systems

All installations of Google Chrome running any version earlier than 152.0.7977.65 are affected, across all platforms where the Actor component is present. The issue applies to the stable channel releases at the time of the advisory.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.8 indicates a critical severity, suggesting that exploitation would grant significant privileges via a crafted HTML page and social engineering. While the attack vector remains remote, the risk is elevated due to the high severity rating and the possibility of bypassing system access restrictions. Applying the vendor patch remains the most effective protection.

Generated by OpenCVE AI on August 26, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later, ensuring the Actor component is updated.
  • If an upgrade is not immediately possible, install the latest available patch from the vendor’s official update channel or use the operating‑system package manager to apply security updates as soon as available.
  • Implement user education and monitoring to reduce reliance on social engineering, ensuring users are aware that malicious HTML content can elevate privileges.

Generated by OpenCVE AI on August 26, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Actor in Google Chrome

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Actor in Google Chrome

Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-269
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:16:48.692Z

Reserved: 2026-08-25T06:09:05.174Z

Link: CVE-2026-79090

cve-icon Vulnrichment

Updated: 2026-08-26T19:16:41.074Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:04.650

Modified: 2026-08-28T17:30:18.587

Link: CVE-2026-79090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:15:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management