Executive brief
Google Chrome's Preload feature contains a flaw that allows incorrect resolution of references, enabling remote attackers to bypass web origin policies. An attacker can craft a malicious HTML page that exploits this vulnerability to circumvent security boundaries that normally isolate content from different websites, potentially leading to unauthorized access to sensitive data or session tokens.
Technical details
The vulnerability exists in Chrome's Preload mechanism due to incorrect reference resolution, which allows bypassing the same-origin policy (SOP). An attacker crafts a malicious HTML page that leverages this flaw to access resources or data from a different origin than the attacker's page. The vulnerability requires network access and user interaction (the user must visit the malicious page), but no authentication is required from the victim. Successful exploitation allows an attacker to read or manipulate cross-origin resources. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65