Description
Incorrect authorization in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Patch Now
AI Analysis

Impact

The vulnerability in Google Chrome prior to 152.0.7977.65 arises from incorrect authorization that permits a remote attacker to bypass the browser’s web origin policy by serving a crafted HTML page. Based on the description, this flaw can allow the attacker to read or manipulate data from another origin, potentially enabling cross‑site scripting or unauthorized data exfiltration. The weakness is classified as CWE‑863.

Affected Systems

Google Chrome browsers running any operating system that have not been updated to version 152.0.7977.65 or later are affected. Users on the stable channel who have not applied the August 2026 update remain at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted HTML page viewed in the browser, requiring only that the victim load the malicious page. Once exploited, the attacker can bypass origin barriers, potentially accessing or modifying data from other sites.

Generated by OpenCVE AI on August 28, 2026 at 18:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Chrome update to 152.0.7977.65 or later
  • Disable or restrict loading of external HTML pages from untrusted sources until the patch is applied, such as configuring browser restrictions or using extensions that block cross‑origin requests
  • Monitor browser logs and web traffic for attempts to load malicious HTML content and investigate any unusual cross‑origin requests

Generated by OpenCVE AI on August 28, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Remote Bypass of Web Origin Policy in Google Chrome

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Remote Bypass of Web Origin Policy in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:06.405Z

Reserved: 2026-08-25T06:10:18.851Z

Link: CVE-2026-79141

cve-icon Vulnrichment

Updated: 2026-08-27T20:31:43.687Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:09.377

Modified: 2026-08-31T16:53:19.160

Link: CVE-2026-79141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses