Description
Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Apply Patch
AI Analysis

Impact

Improper input validation in the NTP Footer feature of Google Chrome for Windows allows a remote attacker who has already compromised the renderer process to bypass the browser’s web origin policy by supplying a specially crafted HTML page. This bypass could enable the attacker to read or modify content from other origins, potentially leading to data theft or injection of malicious code. The weakness is identified as CWE‑20.

Affected Systems

The flaw affects Google Chrome running on Windows machines with versions earlier than 152.0.7977.65. Any installation that has not been updated to at least the 152.0.7977.65 stable release is vulnerable, regardless of the operating system build or user account privileges.

Risk and Exploitability

The vulnerability received a low severity rating by Chromium, and the CVSS score is now 6.5. EPSS is < 1% and the issue is not listed in the CISA KEV catalog. Exploitation requires that an attacker already gains code execution in the renderer process, which is a separate and non‑publicly available attack vector. Because the privilege escalation is limited to the renderer and the exploit is not readily available, the overall risk to users is considered low, but updates should be applied promptly to remove the capability.

Generated by OpenCVE AI on August 26, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later to apply the NTP Footer input validation fix.
  • Enable automatic updates on Chrome to ensure future security patches are received without manual intervention.
  • If a timely upgrade cannot be performed, isolate Chrome processes behind an additional sandbox layer and monitor for anomalous renderer activity to limit potential exploitation until the fix is applied.

Generated by OpenCVE AI on August 26, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome NTP Footer Input Validation Bypass Allowing Origin Policy Circumvention

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Chrome NTP Footer Input Validation Bypass Allowing Origin Policy Circumvention

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:20:55.068Z

Reserved: 2026-08-25T06:09:58.464Z

Link: CVE-2026-79123

cve-icon Vulnrichment

Updated: 2026-08-26T19:20:26.273Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:07.433

Modified: 2026-08-27T01:20:33.300

Link: CVE-2026-79123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation