Description
Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Update Browser
AI Analysis

Impact

The vulnerability arises from incorrect authorization in Chrome’s navigation handling, allowing a crafted web page to bypass the browser’s web origin policy. This flaw can enable an attacker to read or modify data across origins, undermining confidentiality and integrity of the user’s browsing session. It is identified as a CWE‑863 flaw; the description does not detail the exact mechanics, so it is inferred that the error occurs during navigation events where the browser accepts cross‑origin transitions.

Affected Systems

Affected are all Google Chrome browsers on any supported operating system running a version earlier than 152.0.7977.65. The flaw exists in the stable channel and is mitigated by the latest update.

Risk and Exploitability

The CVSS score of 4.3 and an EPSS of less than 1% indicate moderate risk and low exploitation likelihood. No CISA KEV listing means no known public exploit. The attack vector would require the victim to open a malicious HTML page or visit a compromised site, which suggests that social engineering or phishing is the most feasible delivery method.

Generated by OpenCVE AI on August 28, 2026 at 19:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome version 152.0.7977.65 or newer via the official update channel.
  • Configure Chrome Enterprise policy to enforce automatic updates and restrict cross‑origin navigation delegation.
  • Implement site‑wide Content Security Policy headers that limit navigation to trusted origins where possible.

Generated by OpenCVE AI on August 28, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Navigation Authorization Flaw Bypasses Web Origin Policy in Chrome

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Navigation Authorization Flaw Bypasses Web Origin Policy in Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:07.318Z

Reserved: 2026-08-25T06:12:13.932Z

Link: CVE-2026-79237

cve-icon Vulnrichment

Updated: 2026-08-27T20:32:04.650Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:17.967

Modified: 2026-08-28T14:35:18.543

Link: CVE-2026-79237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:15:05Z

Weaknesses