Executive brief
Google Chrome's Controls component contained an authorization flaw that allowed attackers to bypass the web origin policy—a fundamental security boundary that prevents websites from accessing data or capabilities of other websites. An attacker could exploit this by crafting a malicious HTML page to circumvent these protections, potentially allowing unauthorized access to sensitive browser features or cross-origin content.
Technical details
This is an incorrect authorization vulnerability in Google Chrome's Controls component, where access controls were insufficiently enforced. The vulnerability allows a remote attacker to bypass web origin policy via a crafted HTML page, meaning an attacker-controlled website can bypass the Same-Origin Policy or similar protections. The attack requires no authentication and is reachable via network (browsing a malicious website). The fix is available in Chrome version 152.0.7977.65 and later, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65