Executive brief
Google Chrome is a widely used web browser that processes and displays web content from the internet. A flaw in how Chrome enforces access controls for the Document Object Model (DOM) allows attackers to craft malicious web pages that trick the browser into revealing sensitive information a user shouldn't be able to access. An attacker only needs to trick a user into visiting a specially crafted webpage to potentially steal data.
Technical details
This vulnerability is an incorrect authorization flaw in the DOM (Document Object Model) component of Google Chrome. The issue allows a remote attacker to bypass access controls by crafting a malicious HTML page, leading to unauthorized information disclosure. No user interaction beyond visiting a malicious webpage is required; the attack vector is network-based. The vulnerability was fixed in Chrome version 152.0.7977.65 and later. This is a Medium severity issue (CVSS 6.5) that does not require authentication or special privileges to exploit.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65