Description
Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Apply Update
AI Analysis

Impact

Improper input validation in the Network component of Google Chrome allowed a remote attacker to bypass the web origin policy by serving a crafted HTML page. This flaw lets malicious content from one origin interact with resources or data belonging to another origin without the same‑origin restrictions, potentially exposing sensitive information or enabling further attacks. The weakness corresponds to CWE‑20, Input Validation.

Affected Systems

Google Chrome browsers. Versions prior to 153.0.8010.36 are affected. Any installation of Chrome that is older than the stable‑channel update released in September 2026 is vulnerable.

Risk and Exploitability

Chromium indicates a medium severity for this vulnerability. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate but unquantified risk. The CVSS score of 4.3 indicates a moderate severity. The attack likely requires a remote attacker to deliver a malicious HTML document to a victim’s browser; thus the vector is a network‑based, web page delivery. The entry provides no evidence of elevated privileges or code execution, but the breach of origin policy could lead to data exfiltration or unauthorized actions on behalf of the user.

Generated by OpenCVE AI on September 9, 2026 at 20:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later as released by Google.
  • If an update is not immediately feasible, restrict the Chrome user’s network access through corporate firewall or web filter rules that block the delivery of suspicious or unknown HTML content that could trigger the vulnerability.
  • Monitor user browsers for unexpected cross‑origin resource sharing events or alerts from security monitoring tools to detect attempts to exploit the policy bypass.

Generated by OpenCVE AI on September 9, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Web Origin Policy Bypass via Improper Input Validation in Chrome

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Web Origin Policy Bypass via Improper Input Validation in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:26:09.197Z

Reserved: 2026-09-08T22:41:05.734Z

Link: CVE-2026-87573

cve-icon Vulnrichment

Updated: 2026-09-09T17:25:10.564Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:15.057

Modified: 2026-09-09T19:13:28.753

Link: CVE-2026-87573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:00:08Z

Weaknesses
  • CWE-20

    Improper Input Validation