Executive brief
Google Chrome is a widely-used web browser that processes web content including HTML pages. An authorization flaw in Chrome's Network component allowed attackers to bypass system access restrictions by convincing users to visit a specially crafted web page, potentially enabling unauthorized system access or data exposure.
Technical details
This vulnerability is an incorrect authorization issue (CWE-639) in Google Chrome's Network component. The flaw allows a remote attacker to bypass system access restrictions via a crafted HTML page, indicating the vulnerability is reachable through the normal browser rendering pathway without requiring prior authentication. An attacker can exploit this by hosting a malicious HTML page and social engineering a user to visit it. The vulnerability was fixed in Chrome version 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65