Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Web Origin Policy Bypass via Renderer Process Compromise in Google Chrome | |
| First Time appeared |
Google
Google chrome |
|
| Vendors & Products |
Google
Google chrome |
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-08-25T20:10:13.240Z
Reserved: 2026-08-25T06:05:14.198Z
Link: CVE-2026-78961
No data.
Status : Received
Published: 2026-08-25T21:17:52.177
Modified: 2026-08-25T21:17:52.177
Link: CVE-2026-78961
No data.
OpenCVE Enrichment
Updated: 2026-08-25T22:45:06Z