Description
Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-origin data exposure via improper certificate validation in CORS
Action: Upgrade
AI Analysis

Impact

The vulnerability in Google Chrome’s CORS implementation allows a remote attacker to craft network traffic that tricks the browser into trusting a certificate that does not belong to the intended origin, thereby bypassing the web origin policy. This flaw is an example of improper authentication or validation (CWE-295) and can lead to unauthorized access or manipulation of data that should be confined to a trusted domain.

Affected Systems

Google Chrome versions prior to 153.0.8010.36 are affected. Any installation of Chrome that has not yet been updated to the fixed release is vulnerable.

Risk and Exploitability

The CVSS score of 4.3 and an EPSS score of less than 1% indicate a low intrinsic severity and a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, exploitation requires a social‑engineering component, such as persuading a user to visit a maliciously crafted site that employs a forged certificate. If successful, the attacker could compromise the confidentiality or integrity of cross‑origin resources but would not gain arbitrary system control. The overall risk is moderate, pending ongoing monitoring for attack activity.

Generated by OpenCVE AI on September 10, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later where the certificate validation issue is fixed.
  • If an upgrade is not immediately feasible, enforce a restrictive Content Security Policy that limits cross‑origin requests to trusted origins and apply network‑level filtering to block forged certificate traffic.
  • Provide user awareness training to help staff recognize and avoid phishing or social–engineering attempts that may lead to reliance on untrusted certificates.

Generated by OpenCVE AI on September 10, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in CORS Allows Web Origin Policy Bypass

Thu, 10 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in CORS Allows Web Origin Policy Bypass

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Weaknesses CWE-295
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-14T12:51:45.491Z

Reserved: 2026-09-08T22:40:24.115Z

Link: CVE-2026-87551

cve-icon Vulnrichment

Updated: 2026-09-14T12:51:40.698Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:12.683

Modified: 2026-09-14T13:18:58.660

Link: CVE-2026-87551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:45:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation