Description
Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from incorrect authorization checks during navigation in Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass the browser's same‑origin policy by loading a specially crafted HTML page. The attacker can then read or modify resources that belong to other origins, potentially exposing sensitive data or enabling further compromise.

Affected Systems

Affected product is Google Chrome, all stable channel builds older than 152.0.7977.75. The vulnerability applies to the desktop browser only. Users running versions prior to this update are exposed. Chrome may be installed via default OEM channels or via manual installation.

Risk and Exploitability

The CVSS score is not provided; EPSS indicates no data, and the vulnerability is not listed in CISA KEV. Based on the description, the attack requires that the adversary already has compromised the renderer process, which typically implies a prior local or remote code execution step. Hence the risk is considered medium; exploitation is limited to systems where an attacker can inject a malicious page into the renderer. Users should pace update to mitigate.

Generated by OpenCVE AI on September 2, 2026 at 04:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.75 or newer
  • Enforce Chrome auto‑update policies on managed devices to guarantee immediate security patch application
  • If an upgrade cannot be performed immediately, block unsafe navigation by configuring policies that restrict renderer process loading of untrusted content

Generated by OpenCVE AI on September 2, 2026 at 04:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Navigation Authorization Bypass in Google Chrome Enabling Cross-Origin Data Access

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:28.383Z

Reserved: 2026-09-01T16:21:26.703Z

Link: CVE-2026-84355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:29.417

Modified: 2026-09-02T00:18:29.417

Link: CVE-2026-84355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:15:05Z

Weaknesses