Executive brief
Google Chrome is a web browser used globally to access websites and web applications. An attacker who compromised Chrome's rendering component could bypass security boundaries intended to prevent web pages from accessing sensitive data across different websites, potentially allowing theft of user credentials or personal information. This vulnerability requires the attacker to first compromise the renderer process.
Technical details
This vulnerability is an incorrect authorization flaw in Chrome's Extensions component affecting versions prior to 152.0.7977.65. The vulnerability allows a remote attacker who has compromised the renderer process to bypass web origin policy restrictions via a crafted HTML page. The attack vector requires prior compromise of the renderer process, which is a significant precondition. The vulnerability enables policy bypass rather than full code execution, though the practical impact depends on what capabilities the compromised renderer already possesses. Google patched this issue in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-78954 disclosed in Chrome 152 release notes
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65