Junglewise Threat Intelligence

CVE-2026-93379: Google Chrome incorrect authorization in ORB

CVE-2026-93379 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Opaque Response Blocking (ORB) feature contains an authorization flaw that could allow attackers to bypass the browser's site isolation security boundary through a crafted HTML page. Site isolation is a critical security feature that prevents malicious websites from stealing sensitive data from other sites. An attacker exploiting this could potentially access data intended to be protected across site boundaries.

Technical details

This vulnerability exists in Chrome's Opaque Response Blocking (ORB) mechanism and involves incorrect authorization logic that fails to properly enforce site isolation boundaries. An attacker can craft a malicious HTML page that, when viewed in a vulnerable version of Chrome, bypasses the ORB protections and crosses site isolation boundaries. The attack is delivered via network (user visits a malicious webpage) and requires no authentication or user interaction beyond viewing the page. The vulnerability was patched in Chrome 153.0.8010.52 on September 17, 2026. The Chromium security team classified this as High severity, though the CVSS score assigned is 4.3 (medium).

Affected products

  • Google Chrome prior to 153.0.8010.52

Timeline

  • 2026-09-17: disclosed: Public disclosure via Chrome stable channel release
  • 2026-09-17: patched: Fixed in Chrome 153.0.8010.52/.53

References

Related threats