Description
Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows a remote attacker to access data from a different origin by loading a specially crafted HTML page in Google Chrome prior to version 153.0.8010.52. The flaw resides in the handling of permissions, enabling the extraction of cross‑origin information. The impact is information disclosure (CWE‑200), which can compromise user privacy or confidential data without requiring elevated privileges.

Affected Systems

Google Chrome versions prior to 153.0.8010.52, including desktop builds, are affected. The CVE description does not list specific minor versions, so the exact scope of earlier releases is unspecified. The flaw exists in the Permissions module that manages cross‑origin access to resources. Mobile versions are not mentioned in the advisory. It is likely that earlier releases such as 152.x and earlier are vulnerable, but the CVE does not explicitly confirm this.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level, and the EPSS score of < 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but it can still be exploited by an attacker who can serve a malicious HTML page to a victim’s browser. The likely attack path is a remote web page that triggers the permissions check, leading to cross‑origin data leakage. Since the attack requires only the victim to load a crafted page, the vector is remote user interaction.

Generated by OpenCVE AI on September 19, 2026 at 19:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.52 or later
  • If an immediate update is not possible, limit exposure by disabling unnecessary permissions when browsing untrusted sites
  • Stay informed on Chrome security releases and install updates from the stable channel as soon as they become available

Generated by OpenCVE AI on September 19, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6508-1 chromium security update
History

Sat, 19 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Information Leak via Permissions in Google Chrome

Sat, 19 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Information Leak via Permissions in Google Chrome

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-18T13:31:20.931Z

Reserved: 2026-09-17T19:35:00.955Z

Link: CVE-2026-93383

cve-icon Vulnrichment

Updated: 2026-09-18T13:12:05.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T21:17:55.637

Modified: 2026-09-18T17:19:59.160

Link: CVE-2026-93383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor