Description
Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web origin policy bypass
Action: Patch
AI Analysis

Impact

Incorrect authorization in the Input component of Google Chrome prior to version 152.0.7977.65 permits a remote attacker who has already compromised the renderer process to bypass the browser’s same‑origin policy through a specially crafted HTML page. This flaw could enable the attacker to read or manipulate data across origin boundaries, leading to potential theft of confidential information or credential leakage. The severity of the issue is rated medium.

Affected Systems

All installations of Google Chrome running any version earlier than 152.0.7977.65 are affected. The vulnerability exists across all platforms where the renderer process is used.

Risk and Exploitability

The exploit requires the attacker to first gain control of the renderer process, which may arise from other local or remote vulnerabilities. Once this condition is met, the attacker can deliver a crafted webpage that triggers the Input authorization error and violates the origin policy. No publicly available exploit code or proof‑of‑concept is known, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 4.3, and the EPSS score is <1%, indicating a low but non‑zero likelihood of exploitation. Overall, the risk remains moderate, contingent on the presence of a renderer compromise.

Generated by OpenCVE AI on August 28, 2026 at 18:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later, which contains the fix for the improper authorization check in the Input module.
  • Verify that the renderer process remains sandboxed and that the browser’s process model is configured to isolate renderer execution.
  • Actively monitor for unusual or malicious HTML content and restrict extensions or third‑party content that may increase the likelihood of renderer compromise.

Generated by OpenCVE AI on August 28, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Web Origin Policy Bypass via Malicious Input in Google Chrome

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Web Origin Policy Bypass via Malicious Input in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:36:34.847Z

Reserved: 2026-08-25T06:12:30.992Z

Link: CVE-2026-79248

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:19.220

Modified: 2026-08-28T14:35:01.460

Link: CVE-2026-79248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:45:03Z

Weaknesses