Junglewise Threat Intelligence

CVE-2026-78942: Google Chrome incorrect reference resolution in Loader

CVE-2026-78942 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Loader component contains a flaw in how it resolves references, allowing attackers to bypass the browser's same-origin policy—the core security boundary that prevents websites from accessing data from unrelated sites. An attacker sending crafted network traffic could trick a victim's browser into loading resources in violation of this policy, potentially enabling account hijacking, session theft, or unauthorized data access across multiple websites.

Technical details

The vulnerability is an incorrect reference resolution issue in Google Chrome's Loader component, classified as a web origin policy bypass. The flaw allows a remote attacker to circumvent same-origin policy protections through crafted network traffic; no user interaction or prior authentication is required—the vulnerability is triggered by network-level manipulation. The attack vector is network-based, affecting Chrome versions prior to 152.0.7977.65. Google has patched the vulnerability in Chrome 152.0.7977.65 and later. The Chromium project assigned this a Medium security severity rating, with a CVSS v3.1 score of 4.3.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats