Description
Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Origin Policy Bypass
Action: Patch Immediately
AI Analysis

Impact

The flaw is a confused deputy (CWE‑441) in Chrome's prerender component. When a renderer process is compromised, an attacker can create a crafted HTML page that the browser loads in a prerendered context. Because the browser trusts the renderer to enforce origin boundaries, the malicious prerendered page can violate the web origin policy and gain access to resources belonging to another origin. Based on the description, this could allow an attacker to read or manipulate data normally protected by the origin check, potentially leading to data theft or credential compromise; this inference is not directly stated in the CVE text.

Affected Systems

All stable channel releases of Google Chrome prior to 153.0.8010.36 contain the vulnerable prerender implementation. The issue is specific to the Chrome renderer process; therefore, any system running an affected Chrome version without the patch is potentially exposed.

Risk and Exploitability

The CVSS score is 3.1 and the EPSS score is <1%, indicating a low severity and low likelihood of exploitation. The vulnerability is not included in CISA’s KEV catalogue. An attacker would need to achieve remote code execution or exploit a cross‑site scripting flaw to compromise the renderer, then use the confused deputy to escape the origin boundary. Because the attack requires initial renderer compromise, the risk is moderate, but the impact of a successful bypass is high.

Generated by OpenCVE AI on September 9, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • If upgrading is not immediately possible, disable prerendering by adjusting the corresponding Chrome flag or command-line switch.
  • Utilize Chrome’s sandboxing controls and monitor for anomalous renderer activity to reduce privilege misuse.

Generated by OpenCVE AI on September 9, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Prerender Origin Policy Bypass via Compromised Renderer in Chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Prerender Origin Policy Bypass via Compromised Renderer in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-441
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:10:30.502Z

Reserved: 2026-09-08T22:22:48.157Z

Link: CVE-2026-87442

cve-icon Vulnrichment

Updated: 2026-09-09T17:09:48.480Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:00.463

Modified: 2026-09-10T19:19:20.910

Link: CVE-2026-87442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:15:07Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')