Executive brief
Google Chrome's QUIC networking protocol contained a vulnerability that allowed attackers to bypass web origin policy—a fundamental security feature that prevents malicious websites from accessing data belonging to other sites. An attacker could craft a malicious HTML page that, when visited by a user, exploits this flaw to access content from other origins, potentially leading to unauthorized data access or session hijacking.
Technical details
This vulnerability involves an externally controlled reference within the QUIC protocol implementation in Chrome. The flaw allows a remote attacker to bypass the same-origin policy (SOP) via a specially crafted HTML page, enabling unauthorized cross-origin access. The attack requires user interaction (opening a malicious page) but no authentication. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 and later