Executive brief
Google Chrome's Network component failed to properly validate input in versions before 152.0.7977.65, allowing an attacker with access to the renderer process to bypass web origin policies. This vulnerability could enable unauthorized cross-origin data access or manipulation, potentially exposing sensitive information or allowing malicious script execution across security boundaries.
Technical details
This vulnerability is an improper input validation flaw in Chrome's Network component affecting versions prior to 152.0.7977.65. An attacker who has already compromised the renderer process can bypass same-origin policy (web origin policy) protections by crafting a malicious HTML page. The vulnerability requires prior renderer process compromise and network reachability to the affected browser. Successful exploitation allows the attacker to access cross-origin resources or perform unauthorized actions on behalf of the victim. The fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fix released in Chrome 152.0.7977.65