Description
Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Origin Policy Bypass
Action: Immediate Patch
AI Analysis

Impact

Improper input validation in Chrome’s network stack enables an attacker to craft an HTML page that can bypass the browser's origin policy. By violating this isolation boundary, the attacker may access resources, data, or session information from other origins, potentially leading to data theft or session hijacking. Chromium has rated the flaw as medium severity.

Affected Systems

The flaw affects Google Chrome browsers prior to version 152.0.7977.65. All builds before this revision are vulnerable until a patch is applied.

Risk and Exploitability

The EPSS score is less than 1% and the CVSS score of 4.3 indicates medium severity. The vulnerability is not listed in CISA KEV, indicating no confirmed active exploitation at this time. The likely attack vector is a remote attacker delivering a crafted web page that the user opens, which triggers the origin policy bypass. Although the flaw does not grant arbitrary code execution, it offers a moderate risk by compromising cross‑origin isolation until mitigated by updating the browser.

Generated by OpenCVE AI on August 28, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (152.0.7977.65 or newer) to remove the input validation flaw.
  • Avoid visiting untrusted web pages that could contain malicious content designed to exploit the flaw until the update is applied.
  • If you manage corporate Chrome deployments, use enterprise policies to restrict cross‑origin requests or to enforce safe browsing until a patch is available.

Generated by OpenCVE AI on August 28, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Input Validation Vulnerability Enabling Origin Policy Bypass

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chrome Network Input Validation Vulnerability Enabling Origin Policy Bypass

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:46:43.211Z

Reserved: 2026-08-25T06:12:36.391Z

Link: CVE-2026-79251

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:19.557

Modified: 2026-08-28T14:32:56.723

Link: CVE-2026-79251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:30:08Z

Weaknesses
  • CWE-20

    Improper Input Validation