Description
Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Web origin policy bypass
Action: Apply Chrome Update
AI Analysis

Impact

The flaw occurs when a released resource in Chrome’s core allows a renderer process that has already been compromised to override the same‑origin policy. An attacker can serve a specially crafted HTML page that exploits this flaw, enabling reading or modification of data from another origin, which can lead to data theft or manipulation of the user’s browsing session.

Affected Systems

Google Chrome browsers running any version prior to 154.0.8037.57 are affected. The issue was fixed in the 154.0.8037.57 update released in September 2026.

Risk and Exploitability

The vulnerability is not listed in the CISA KEV catalog. Chromium assigns it a medium severity, but no CVSS score is publicly available. No EPSS score is available, so the likelihood of exploitation is uncertain; however, the attacker must first compromise the renderer process, indicating a need for significant pre‑existing foothold. Once that is achieved, a crafted HTML page can be served to bypass the origin policy. The overall risk is moderate but warrants timely remediation.

Generated by OpenCVE AI on September 30, 2026 at 00:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 154.0.8037.57 or later through the latest stable channel update.
  • Configure enterprise policies to enforce the minimum supported Chrome version or automatically install patches.
  • Review and enforce sandboxing settings to limit renderer privileges, ensuring that renderer processes run with the least privileges necessary.

Generated by OpenCVE AI on September 30, 2026 at 00:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Wed, 30 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Exploit Allows Cross-Origin Policy Bypass in Chrome

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-672
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T17:31:44.441Z

Reserved: 2026-09-22T05:10:54.431Z

Link: CVE-2026-95366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:30.387

Modified: 2026-09-29T18:56:13.190

Link: CVE-2026-95366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:15:16Z

Weaknesses
  • CWE-672

    Operation on a Resource after Expiration or Release