Description
Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

Chrome provides SiteSettings to control permissions such as camera, microphone, and site access. An incorrect authorization check in the SiteSettings component allowed a remote attacker to create a crafted HTML page that could modify these settings, effectively bypassing system access restrictions. This flaw is a CWE‑863 authorization bypass that lets malicious content change security settings without user consent, potentially granting the attacker higher privileges or access to protected data.

Affected Systems

All Chrome releases prior to version 152.0.7977.75 are impacted. Users who have not upgraded to this or later versions are at risk.

Risk and Exploitability

The CVSS score of 6.5 reflects a medium severity. The EPSS score is < 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the issue requires delivery of a crafted HTML page, the likely attack vector is a remote or local web page that the user opens in Chrome. Attack conditions include the user enabling SiteSettings changes; once the malicious page is loaded, the attacker can alter or circumvent system access controls. Limited exploit data makes precise likelihood uncertain, but the medium severity indicates a non‑negligible risk.

Generated by OpenCVE AI on September 3, 2026 at 10:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 152.0.7977.75 or newer to apply the vendor’s fix.
  • If an update cannot be installed immediately, configure Chrome Enterprise policy to disable automated or user‑initiated changes to SiteSettings for untrusted websites.
  • Avoid opening unexpected or suspicious HTML files in Chrome; only load content from trusted sources.

Generated by OpenCVE AI on September 3, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Authority Bypass in Chrome’s SiteSettings via Crafted HTML

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Authority Bypass in Chrome’s SiteSettings via Crafted HTML

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T19:05:03.821Z

Reserved: 2026-09-01T16:20:34.546Z

Link: CVE-2026-84332

cve-icon Vulnrichment

Updated: 2026-09-02T18:41:02.000Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T00:18:28.090

Modified: 2026-09-03T17:10:22.183

Link: CVE-2026-84332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:00:03Z

Weaknesses