Description
Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Cross‑Origin Data Leak
Action: Update Chrome
AI Analysis

Impact

A crafted HTML page can trigger a flaw in Navigation handling within Google Chrome that allows a remote attacker to read data from another origin. The vulnerability is a case of information disclosure (CWE‑203) and could lead to the exposure of sensitive site information to an attacker controlling a malicious web page. This issue is not a code execution or denial‑of‑service flaw; its outcome is the unintended release of cross‑origin content rather than system compromise.

Affected Systems

The flaw exists in Google Chrome on the stable channel for any installation before version 153.0.8010.36. Users running earlier stable builds are vulnerable until the update that corrects the navigation discrepancy is installed. No other vendors or product variants are listed in the advisory.

Risk and Exploitability

An EPSS score of 0.00241 indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, so publicly known exploitation data is limited. The CVSS score of 4.3 confirms a medium‑severity rating, and the EPSS score of 0.00241 indicates a very low exploitation probability, so the actual risk to an organization depends on the likelihood that an attacker can serve a malicious page to the target user. Because the flaw requires a crafted page in the victim’s browser, the threat vector is typically remote via the web.

Generated by OpenCVE AI on September 9, 2026 at 20:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later, which contains the fix for the navigation discrepancy.
  • Configure a strict content security policy that limits cross‑origin data access, such as "default-src 'none'; script-src 'self';" to reduce the chance of accidental leakage.
  • Continuously monitor Google Chrome security releases and update appliances promptly to stay protected against related issues.

Generated by OpenCVE AI on September 9, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Navigation Discrepancy in Chrome

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Navigation Discrepancy in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:28:45.781Z

Reserved: 2026-09-08T22:39:16.929Z

Link: CVE-2026-87516

cve-icon Vulnrichment

Updated: 2026-09-09T17:27:50.291Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:08.690

Modified: 2026-09-09T19:15:55.707

Link: CVE-2026-87516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses