Description
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Site isolation bypass via crafted HTML in a compromised renderer
Action: Apply Patch
AI Analysis

Impact

The flaw is an incorrect authorization check in Chrome’s Network component that, prior to version 152.0.7977.65, allows a remote attacker who has already compromised the renderer process to bypass site isolation by serving a specially crafted HTML page. The flaw does not enable arbitrary code execution by itself; it simply removes the boundary that normally prevents a malicious page from accessing or interfering with data from other sites. The weakness is classified as an authorization bypass (CWE-863).

Affected Systems

All installations of Google Chrome older than 152.0.7977.65 are affected. The vulnerability impacts every supported operating system because Chrome’s network layer and renderer are common across platforms. Users who remain on earlier releases of the browser remain exposed until they upgrade.

Risk and Exploitability

Chromium rates the issue as Medium, with a CVSS score of 3.1. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Exploitation requires an attacker first to gain control of the renderer process, typically by luring the user to load malicious web content. Once renderer compromise is achieved, the crafted HTML triggers the authorization bypass and breaks the isolation boundary, exposing the affected user to potential data theft or phishing. The overall risk is moderate to high for users who navigate untrusted content, but the absence of widespread exploitation reduces immediate urgency.

Generated by OpenCVE AI on August 31, 2026 at 17:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Chrome 152.0.7977.65 or newer via the official stable channel release
  • In managed environments, configure the Chrome update engine to push the fix automatically
  • Until the patch can be applied, restrict access to untrusted sites and monitor renderer behavior for anomalous activity

Generated by OpenCVE AI on August 31, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Mon, 31 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Chrome Network Authorization Bypass Enables Site Isolation Exploit via Malicious HTML

Mon, 31 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Authorization Bypass Enables Site Isolation Exploit via Malicious HTML

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-31T15:20:56.061Z

Reserved: 2026-08-25T06:11:06.195Z

Link: CVE-2026-79186

cve-icon Vulnrichment

Updated: 2026-08-31T15:20:51.960Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:12.267

Modified: 2026-08-31T18:59:43.807

Link: CVE-2026-79186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T17:45:02Z

Weaknesses