Impact
The vulnerability in Google Chrome prior to 152.0.7977.65 arises from incorrect authorization that permits a remote attacker to bypass the browser’s web origin policy by serving a crafted HTML page. Based on the description, this flaw can allow the attacker to read or manipulate data from another origin, potentially enabling cross‑site scripting or unauthorized data exfiltration. The weakness is classified as CWE‑863.
Affected Systems
Google Chrome browsers running any operating system that have not been updated to version 152.0.7977.65 or later are affected. Users on the stable channel who have not applied the August 2026 update remain at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted HTML page viewed in the browser, requiring only that the victim load the malicious page. Once exploited, the attacker can bypass origin barriers, potentially accessing or modifying data from other sites.
OpenCVE Enrichment
Debian DLA
Debian DSA