Impact
This flaw is an authorization error in the PushAPI component of Google Chrome. When the renderer process is compromised, a malicious site can send a specially crafted HTML page that tricks the browser into treating data as originating from an arbitrary web origin. The attacker can therefore bypass the same-origin policy and read or modify resources that belong to other domains. The weakness maps to the Common Weakness Enumeration CWE‑863, which concerns improper authorization schemes.
Affected Systems
Affected systems are any installations of Google Chrome prior to version 153.0.8010.36. The problem was fixed in Chrome 153.0.8010.36 and later stable releases, as announced in the September 2026 stable channel update. Users running earlier versions, especially those on Windows, macOS, Linux or Chrome OS, are susceptible.
Risk and Exploitability
The built-in Chromium rating for this issue is Medium, and the CVSS score of 3.1 indicates low severity. It is not currently recorded in the CISA KEV catalog. An exploit requires an attacker to first gain control of the renderer process, after which the crafted page can be delivered. No public exploits are known, and the EPSS score is < 1%. Given that many users run the latest Chrome builds, the practical risk is limited, but the vulnerability is exploitable by privileged local or remote attackers who can compromise renderers.
OpenCVE Enrichment
Debian DLA
Debian DSA