Junglewise Threat Intelligence

CVE-2026-78961: Google Chrome incorrect authorization in Core

CVE-2026-78961 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an incorrect authorization vulnerability in its Core component that could allow an attacker to bypass web origin policy protections. The vulnerability requires the attacker to first compromise the browser's renderer process and use social engineering, potentially enabling the bypass of security boundaries that normally isolate websites from each other.

Technical details

This vulnerability is an incorrect authorization flaw in Google Chrome's Core component affecting versions prior to 152.0.7977.65. The vulnerability requires an attacker to have already compromised the renderer process and leverages social engineering to bypass the same-origin policy through a crafted HTML page. While the attack requires substantial preconditions (renderer process compromise and user interaction), successful exploitation would allow policy bypass that could lead to unauthorized access to cross-origin data. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats