Description
Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Origin policy bypass enabling cross‑origin data theft or injection
Action: Apply Patch
AI Analysis

Impact

Google Chrome versions older than 152.0.7977.65 contain an improper access control flaw in the implementation of Web Workers. An attacker can craft a malicious HTML page that, when opened in the victim’s browser, triggers the Workers API and bypasses the browser’s web origin policy. The result is that a page from one origin can gain unauthorized access to resources, cookies, or data belonging to another origin, allowing data theft, content injection, or unauthorized manipulation within the user’s browsing session.

Affected Systems

The vulnerability affects Google Chrome for desktop users running any build prior to version 152.0.7977.65. The flaw is specific to the Workers implementation in the stable channel and is not present in later releases.

Risk and Exploitability

The flaw is classified as medium severity by Chromium. The CVSS score is 4.3 and the EPSS score is < 1%. The attack requires a user to load a specially crafted web page, and no public exploit code or known real‑world incidents have been reported. The vulnerability is also not listed in the CISA KEV catalog. Given the widespread use of Chrome, the risk is moderate; a determined attacker could distribute malicious content that takes advantage of the flaw but the likelihood of an exploit in the wild remains uncertain without further evidence.

Generated by OpenCVE AI on August 28, 2026 at 18:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later
  • Ensure Chrome’s automatic update feature is enabled so future patches are applied promptly
  • If an immediate update is not possible, configure enterprise Chrome policies to disable or restrict Web Worker usage to reduce the attack surface

Generated by OpenCVE AI on August 28, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Chrome Web Workers Access Control Bypass Exploiting Origin Policy

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Web Workers Access Control Bypass Exploiting Origin Policy

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-284
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:46:43.029Z

Reserved: 2026-08-25T06:11:25.497Z

Link: CVE-2026-79201

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:13.930

Modified: 2026-08-28T14:36:13.477

Link: CVE-2026-79201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses