Executive brief
Google Chrome's StreamsAPI component in versions prior to 152.0.7977.65 contains a flaw that allows remote attackers to bypass the web origin policy—a critical browser security boundary that prevents malicious websites from accessing data or functionality from legitimate sites. An attacker can exploit this by tricking a user into visiting a crafted webpage, potentially gaining unauthorized access to sensitive functionality or data from privileged pages.
Technical details
The vulnerability is an improper resource exposure in StreamsAPI, a component that handles streaming data within the Chrome browser. The flaw allows a remote attacker to bypass the same-origin policy via a maliciously crafted HTML page. The attack requires user interaction (visiting the attacker's webpage) but does not require authentication. By successfully exploiting this, an attacker can access resources or functionality from a privileged page that should be isolated by the web origin boundary. The vulnerability is fixed in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65