Executive brief
Google Chrome is a widely used web browser that processes web pages and executes content. This vulnerability allows an attacker who has compromised the browser's rendering process to bypass the same-origin policy, potentially accessing data from different websites that the user is viewing. The attack requires prior compromise of the renderer process and relies on a crafted HTML page to exploit.
Technical details
This is a missing authorization vulnerability in Chrome's Preload functionality. The vulnerability exists in versions prior to 152.0.7977.65 and can be exploited by a remote attacker who has already compromised the renderer process. The flaw allows bypassing web origin policy through a crafted HTML page, effectively breaking the browser's same-origin policy boundary. Attack preconditions include prior renderer process compromise; however, once that is achieved, the attacker can execute the exploit via crafted HTML. The vulnerability has been patched in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65