Impact
The flaw occurs when a released resource in Chrome’s core allows a renderer process that has already been compromised to override the same‑origin policy. An attacker can serve a specially crafted HTML page that exploits this flaw, enabling reading or modification of data from another origin, which can lead to data theft or manipulation of the user’s browsing session.
Affected Systems
Google Chrome browsers running any version prior to 154.0.8037.57 are affected. The issue was fixed in the 154.0.8037.57 update released in September 2026.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog. Chromium assigns it a medium severity, but no CVSS score is publicly available. No EPSS score is available, so the likelihood of exploitation is uncertain; however, the attacker must first compromise the renderer process, indicating a need for significant pre‑existing foothold. Once that is achieved, a crafted HTML page can be served to bypass the origin policy. The overall risk is moderate but warrants timely remediation.
OpenCVE Enrichment
Debian DSA