Description
Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from an incorrect authorization check in the Cross‑Origin Resource Sharing (CORS) handling of Google Chrome versions earlier than 153.0.8010.36. A remote attacker who has already gained control of the renderer process can craft a malicious HTML page that tricks the browser into treating cross‑origin requests as legitimate. The result is a bypass of the web origin policy, enabling the attacker to read protected resources, execute privileged scripts, or exfiltrate data that should be confined to a single origin. This flaw is classified as a medium‑severity issue by Chromium security, reflecting its potential impact on confidentiality and integrity.

Affected Systems

The affected product is Google Chrome. All versions before 153.0.8010.36 are vulnerable, regardless of operating system. Users running a legacy or manually managed installation that has not yet updated to the 153.0.8010.36 release or later are susceptible.

Risk and Exploitability

An exploitable path requires an attacker to have already compromised the renderer process, which is a more advanced prerequisite than a typical remote attack. Because the flaw is a CORS logic error, exploitation is limited to web origins served by a compromised renderer. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. Nevertheless, once the renderer is compromised, the ability to bypass the same‑origin policy can lead to significant data leakage or scripting attacks. The CVSS score of 3.1 indicates a low severity, but the risk remains contingent on the existing compromise of the renderer process.

Generated by OpenCVE AI on September 9, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later using automatic updates or a manual installation if you manage Chrome manually.
  • If an update cannot be applied immediately, restrict remote debugging by configuring the Chrome policy "AllowRemoteDebugging" to false (or disabling the corresponding chrome://flags), which reduces the attacker’s ability to interact with a compromised renderer.
  • Monitor for signs of renderer process compromise and consider isolating sensitive applications in separate browsing contexts or using Chrome’s Site Isolation feature for enhanced protection.

Generated by OpenCVE AI on September 9, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title CORS Authorization Bypass in Chrome Allows Remote Web Origin Policy Violation

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title CORS Authorization Bypass in Chrome Allows Remote Web Origin Policy Violation

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:10:15.976Z

Reserved: 2026-09-08T22:38:23.406Z

Link: CVE-2026-87485

cve-icon Vulnrichment

Updated: 2026-09-09T17:09:47.059Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:05.210

Modified: 2026-09-09T19:17:07.543

Link: CVE-2026-87485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:00:13Z

Weaknesses