Description
Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass enabling origin policy violation
Action: Patch
AI Analysis

Impact

The flaw is an incorrect authorization mechanism in Chrome Controls that allows a remote attacker to create a crafted HTML page and bypass Chrome’s same‑origin policy. By exploiting this, an attacker can read or write data across origins, leaking confidential information or injecting malicious content into contexts that should be protected. The weakness is classified as CWE‑863: Improper Authorization.

Affected Systems

All installations of Google Chrome that have not yet upgraded to version 152.0.7977.65 are affected, regardless of platform. The CVE data does not specify which operating systems or build channels (e.g., Stable, Beta) are impacted, so affected systems are inferred to include any Chrome build that contains the vulnerable Controls feature prior to the announced patch.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity vulnerability, and the EPSS score of < 1 % signals a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. According to the CVE description, exploitation would require a malicious web page that lures a user to visit it. Once a user loads the crafted page, the attacker can execute cross‑origin requests that are normally blocked, enabling data theft or injection. The CVE data does not mention any documented exploitation.

Generated by OpenCVE AI on August 27, 2026 at 20:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or newer immediately.
  • Ensure that automatic updates for Chrome are enabled so that future patches are applied automatically.
  • If an immediate update is not possible, disable the vulnerable Controls feature through chrome://flags or enforce an enterprise policy to block it until the patch is installed.

Generated by OpenCVE AI on August 27, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Chrome Controls Enables Origin Policy Bypass

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Chrome Controls Enables Origin Policy Bypass

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T15:30:13.606Z

Reserved: 2026-08-25T06:12:46.338Z

Link: CVE-2026-79261

cve-icon Vulnrichment

Updated: 2026-08-27T15:30:06.826Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:20.667

Modified: 2026-08-31T16:51:05.310

Link: CVE-2026-79261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T20:45:07Z

Weaknesses