Description
Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome provides SiteSettings to control permissions such as camera, microphone, and site access. An incorrect authorization check in the SiteSettings component allowed a remote attacker to create a crafted HTML page that could modify these settings, effectively bypassing system access restrictions. This flaw is a CWE‑863 authorization bypass that lets malicious content change security settings without user consent, potentially granting the attacker higher privileges or access to protected data.

Affected Systems

All Chrome releases prior to version 152.0.7977.75 are impacted. Users who have not upgraded to this or later versions are at risk.

Risk and Exploitability

The Chromium severity is listed as Medium. No EPSS score is currently available, and the vulnerability is not present in the CISA KEV catalog. Because the issue requires delivery of a crafted HTML page, the likely attack vector is a remote or local web page that the user opens in Chrome. Attack conditions include the user enabling SiteSettings changes; once the malicious page is loaded, the attacker can alter or circumvent system access controls. Limited exploit data makes precise likelihood uncertain, but the medium severity indicates a non‑negligible risk.

Generated by OpenCVE AI on September 2, 2026 at 04:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 152.0.7977.75 or newer to apply the vendor’s fix.
  • If an update cannot be installed immediately, configure Chrome Enterprise policy to disable automated or user‑initiated changes to SiteSettings for untrusted websites.
  • Avoid opening unexpected or suspicious HTML files in Chrome; only load content from trusted sources.

Generated by OpenCVE AI on September 2, 2026 at 04:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Authority Bypass in Chrome’s SiteSettings via Crafted HTML

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:28.749Z

Reserved: 2026-09-01T16:20:34.546Z

Link: CVE-2026-84332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:28.090

Modified: 2026-09-02T00:18:28.090

Link: CVE-2026-84332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:15:05Z

Weaknesses