Description
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass in Chrome’s SiteIsolation
Action: Patch Browser
AI Analysis

Impact

The vulnerability is an incorrect authorization check in Google Chrome’s SiteIsolation feature. It allows a remote attacker who has already compromised the renderer process to bypass site isolation by serving a crafted HTML page. This flaw enables the attacker to act with privileges beyond those granted to a normal renderer process, according to the CWE‑863 classification.

Affected Systems

Google Chrome versions prior to 152.0.7977.65 on any platform are affected, including the stable channel. Any user running an older version of Chrome that may be exposed to a compromised renderer process is vulnerable.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, and the EPSS score is less than 1%, suggesting a low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires an initial compromise of the renderer process and the use of social engineering to deliver a crafted HTML page. While the attack surface is limited by the need for that preexisting compromise, the impact on confidentiality and integrity within the browser is notable if the renderer is subverted.

Generated by OpenCVE AI on August 28, 2026 at 18:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or newer
  • If an update cannot be applied immediately, configure enterprise policy settings to enforce stricter SiteIsolation rules and limit renderer process privileges
  • Monitor for social engineering attempts and maintain secure browser configuration to reduce exposure

Generated by OpenCVE AI on August 28, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:03:48.432Z

Reserved: 2026-08-25T06:11:11.052Z

Link: CVE-2026-79191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:12.817

Modified: 2026-08-28T14:36:26.883

Link: CVE-2026-79191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses