Junglewise Threat Intelligence

CVE-2026-78947: Google Chrome web origin policy bypass in Chromium

CVE-2026-78947 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a flaw in Chromium that allows remote attackers to bypass web origin policy protections—the security boundaries that prevent websites from accessing data belonging to other domains. By tricking a user into installing a malicious Chrome extension, an attacker can circumvent these protections, potentially gaining unauthorized access to sensitive data from other websites the user visits. This could lead to theft of login credentials, personal information, or session data across multiple websites.

Technical details

This vulnerability is an incomplete cleanup issue in Chromium's web origin policy enforcement mechanism, allowing an origin policy bypass through a crafted Chrome extension. The attack requires social engineering to convince a user to install the malicious extension; once installed, the extension can access resources across different web origins that should normally be restricted. The vulnerability affects Google Chrome versions prior to 152.0.7977.65 on Windows, Mac, and Linux. Google has patched this issue in Chrome 152.0.7977.65, and the patch should be applied immediately given the security nature of origin policy violations.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed

References

Related threats