Executive brief
Google Chrome's Viz component contains a missing authorization vulnerability that allows an attacker who has already compromised the browser's renderer process to bypass web origin policy restrictions. This could enable a compromised renderer to access content or perform actions across different websites, potentially exposing user data or enabling malicious behavior across origins.
Technical details
This is a missing authorization vulnerability in the Viz component of Google Chrome affecting versions prior to 152.0.7977.65. The vulnerability requires an attacker to have already compromised the renderer process, which runs web content in a sandboxed environment. By crafting a malicious HTML page, an attacker can exploit the authorization bypass to circumvent web origin policy restrictions. The fix is available in Chrome 152.0.7977.65 and later versions. Attack vector is network-based but requires a prior renderer compromise, making it a post-exploitation issue rather than a direct attack vector.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fix available in Chrome 152.0.7977.65