Description
Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: System Access Bypass
Action: Immediate Patch
AI Analysis

Impact

Missing authorization in the Network component of Google Chrome before 152.0.7977.65 allows a remote attacker to bypass system access restrictions via a crafted HTML page. The flaw permits unauthorized access to privileged browser operations without proper permission checks, potentially exposing sensitive data or enabling additional attacks.

Affected Systems

Google Chrome browsers on all platforms running versions earlier than 152.0.7977.65 are affected. Versions 152.0.7977.65 and later contain the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating medium severity. An attacker can host a malicious HTML page that, when viewed by a user, triggers unverified network requests that bypass system access controls. The EPSS score is <1% and the flaw is not listed in CISA KEV, indicating limited public exploitation data. Nonetheless, the ability to bypass system access could lead to privilege escalation or data exposure if the malicious content can reach the targeted machine.

Generated by OpenCVE AI on August 29, 2026 at 00:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Chrome version 152.0.7977.65 or newer to all systems that run Chrome.
  • Disable or remove any Chrome extensions that modify or bypass network access controls until the update is fully deployed.
  • Verify and update Chrome’s enterprise policy settings to enforce proper authorization controls and reflect the corrected behavior.

Generated by OpenCVE AI on August 29, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Chrome Browsers Vulnerability: Missing Authorization Allows Bypass of System Access Restrictions

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chrome Browsers Vulnerability: Missing Authorization Allows Bypass of System Access Restrictions

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:13:35.583Z

Reserved: 2026-08-25T06:09:23.396Z

Link: CVE-2026-79099

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:05.447

Modified: 2026-08-31T14:58:28.940

Link: CVE-2026-79099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses