Executive brief
Google Chrome's Core component contains a missing authorization vulnerability that could allow an attacker who has already compromised the browser's renderer process to forge the address bar, potentially tricking users into visiting malicious websites. This is a post-compromise risk where an attacker with partial control can escalate their ability to deceive users about which website they are visiting.
Technical details
This is a missing authorization vulnerability in Chrome's Core component that affects versions prior to 152.0.7977.65. The vulnerability requires an attacker to have already compromised the renderer process—a significant precondition—and then allows them to spoof the address bar via crafted HTML. The attack vector is network-based, but conditional on prior renderer compromise. An attacker exploiting this can make the browser display a false URL in the address bar, misleading users about the website they are on. The vulnerability was fixed in Chrome 152.0.7977.65, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Published via Chrome Releases blog
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65