Executive brief
Google Chrome's Navigation component contains an authorization flaw that allows remote attackers to bypass same-origin policy protections through a crafted HTML page. An attacker could potentially access or modify content from other web origins, compromising user data and session security.
Technical details
This vulnerability is an incorrect authorization flaw in the Navigation component of Google Chrome. It allows a remote attacker to bypass the web origin policy (same-origin policy) by serving a specially crafted HTML page to a victim. No authentication is required; the attack is network-based and exploits a weakness in how Chrome enforces origin boundaries during navigation. A successful exploit could allow an attacker to access cross-origin data or perform actions on behalf of the user in other origins. The vulnerability is fixed in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Published in Chrome Stable Channel Update
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65