Description
Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Origin Policy Bypass
Action: Patch Update
AI Analysis

Impact

Improper input validation in Chrome's Preload feature allows a remote attacker who has compromised the renderer process to bypass the browser's web origin policy by serving a specially crafted HTML page. The flaw is a CWE‑20 input validation weakness. This bypass could let the attacker access resources that should be isolated by origin, such as reading data from other sites loaded in the same tab or injecting malicious content. The CVE description does not explicitly confirm further exploitation, so any impact beyond policy bypass is inferred from the stated behavior.

Affected Systems

This vulnerability affects all Google Chrome versions released before 152.0.7977.65 that include the Preload feature, across all operating systems and platforms supported by that release. End users of the stable channel should verify their installed Chrome build and plan an update if they are running a vulnerable version.

Risk and Exploitability

The CVSS score is 4.3, and the EPSS score is < 1%, indicating that the exploitation probability is not well characterized. The vulnerability is not listed in the CISA KEV catalog, suggesting there are no known active exploits in the wild. The attacker needs prior compromise of the renderer process to exploit the flaw, which is a non‑trivial prerequisite. Overall, the risk is moderate, and the most effective mitigation is to apply the vendor‑provided fix.

Generated by OpenCVE AI on August 28, 2026 at 18:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Chrome 152.0.7977.65 or later across all endpoints to address the Preload input validation flaw.
  • If preloading is not essential for your environment, disable the Preload feature via Chrome policies to reduce exposure while a permanent fix is pending.
  • Continuously monitor Chrome security advisories and promptly install subsequent releases to maintain protection.

Generated by OpenCVE AI on August 28, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Sat, 29 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Chrome Preload Input Validation Bug Enables Origin Policy Bypass

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Preload Input Validation Bug Enables Origin Policy Bypass

Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:36:34.447Z

Reserved: 2026-08-25T06:11:40.200Z

Link: CVE-2026-79214

cve-icon Vulnrichment

Updated: 2026-08-27T19:28:44.743Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:15.380

Modified: 2026-08-28T14:35:42.607

Link: CVE-2026-79214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses
  • CWE-20

    Improper Input Validation