Executive brief
Google Chrome is a web browser used by billions of users worldwide to access websites and web applications. A flaw in the Select component allows attackers to bypass the web origin policy—a critical security mechanism that prevents malicious websites from accessing data intended for legitimate sites—by tricking users into visiting crafted HTML pages. This could enable unauthorized data access across websites.
Technical details
This is an incorrect authorization vulnerability in the Select component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker to bypass the web origin policy, which enforces security boundaries between different websites. The attack vector is network-based and requires user interaction (visiting a crafted HTML page). An attacker can craft a malicious HTML page that, when visited, exploits the authorization flaw to circumvent origin restrictions. The vulnerability was patched in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65