Description
Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Bypass Site Isolation
Action: Patch
AI Analysis

Impact

An incorrect reference resolution bug in Google Chrome’s Speech feature allows a remote attacker who has already compromised the renderer process to bypass the browser’s site isolation boundaries by loading a specially crafted HTML page. This enables the attacker to potentially access or manipulate cross‑site data that should be contained within separate processes, compromising confidentiality and integrity of isolated sites.

Affected Systems

The vulnerability affects Google Chrome versions prior to 152.0.7977.65 on all platforms that run the desktop stable channel. Any site that could be reached through the compromised renderer process is subject to a site isolation bypass.

Risk and Exploitability

The CVSS score of 3.1 indicates a Low severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first gain control of a renderer process, after which a crafted HTML page can trigger the reference resolution flaw. While no public exploits are reported, the potential for data leakage and cross‑site manipulation raises concerns for browsers that rely on site isolation for security.

Generated by OpenCVE AI on August 28, 2026 at 18:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or newer, which contains the fixed Speech reference resolution logic.
  • Confirm that the site isolation setting remains enabled after the update in Chrome’s advanced security options.
  • Apply additional Content Security Policy rules to restrict the execution of hostile or unexpected JavaScript within loaded pages to further mitigate the impact of potential future reference resolution bugs.

Generated by OpenCVE AI on August 28, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Speech Reference Resolution in Chrome

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Speech Reference Resolution in Chrome
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:09:15.407Z

Reserved: 2026-08-25T06:09:24.488Z

Link: CVE-2026-79103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:05.557

Modified: 2026-08-28T14:38:18.860

Link: CVE-2026-79103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference