Executive brief
Google Chrome's New Tab Page (NTP) Footer component on Windows contained insufficient input validation that could be exploited by an attacker who had already compromised Chrome's renderer process. A malicious actor could craft a webpage to bypass web origin policy restrictions, potentially allowing unauthorized access to sensitive data or operations across different websites. This vulnerability required renderer process compromise as a prerequisite, limiting but not eliminating real-world risk.
Technical details
The vulnerability is an improper input validation flaw in the NTP Footer component of Google Chrome on Windows (prior to version 152.0.7977.65). The weakness allows an attacker who has already achieved renderer process compromise to bypass the same-origin policy through a crafted HTML page. The attack vector requires network access and prior compromise of the renderer process; however, once that precondition is met, the attacker can craft malicious HTML to circumvent browser security boundaries. Google fixed this issue in Chrome 152.0.7977.65 and later versions. The Chromium project assigned a Low severity rating internally, though the CVSS score is 6.5 (medium).
Affected products
- Google Chrome prior to 152.0.7977.65 on Windows
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65