Executive brief
Google Chrome's web cache component contains a flaw that allows remote attackers to bypass web origin policy restrictions. An attacker could craft a malicious HTML page that, when loaded in a vulnerable version of Chrome, exploits this vulnerability to access resources or data from different web origins, potentially leading to unauthorized data exposure or session hijacking.
Technical details
This vulnerability is a web origin policy bypass in Chrome's Cache component caused by incorrect reference resolution. The flaw can be exploited by a remote attacker through a crafted HTML page that triggers the vulnerable code path. No authentication or elevated privileges are required; the attack is triggered by a user visiting a malicious website. An attacker can bypass the same-origin policy, potentially allowing access to sensitive data from other origins. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65