Description
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Incorrect USB Authorization
Action: Immediate Patch
AI Analysis

Impact

An incorrect authorization check in Chrome’s USB handling allows a remote attacker to craft a malicious HTML page that invokes USB APIs. The attacker relies on social engineering to get a user to load the page, then Chrome permits USB access that should have been rejected, granting the attacker unauthorized system access. The vulnerability is identified as CWE‑863 and is graded as a medium severity flaw in Chromium’s internal scale.

Affected Systems

The flaw affects Google Chrome versions installed before 152.0.7977.65 on desktop operating systems. Users on earlier stable releases that have not yet applied the update are at risk until they upgrade to the patched build.

Risk and Exploitability

The CVSS score is 4.3, and the EPSS score is < 1%, so the exact exploitation probability is unknown. However, the vulnerability requires user interaction with a malicious web page, suggesting a remote social‑engineering vector rather than an automated attack loop. The flaw is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation has been reported.

Generated by OpenCVE AI on August 28, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later
  • Configure Chrome policy to block or restrict USB requests from web pages
  • Avoid visiting untrusted websites or clicking links that prompt USB access until the update is applied

Generated by OpenCVE AI on August 28, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization via USB in Google Chrome Enables Unauthorized System Access

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization via USB in Google Chrome Enables Unauthorized System Access

Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:45:59.915Z

Reserved: 2026-08-25T06:11:38.084Z

Link: CVE-2026-79211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:15.050

Modified: 2026-08-31T14:15:36.623

Link: CVE-2026-79211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:15:04Z

Weaknesses