Skip to content
GoogleCVE-2026-78954

Google Chrome: improper authorization

Medium4.3CVE-2026-78954 · Published Aug 25, 2026 · updated Aug 28, 2026

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 152.0.7977.65, < 152.0.7977.65152.0.7977.65
Details and references

More Google advisories

All Google
Advisory
Improper control of a resource through its lifetime in Workers in Google Chrome...
Low3.1Aug 25
Google Chrome: use after free
Critical9.6Aug 25
Google Chrome: information disclosure
Medium6.5Aug 25
Google Chrome: integer overflow
High8.3Aug 25
Google Chrome: information disclosure
Medium6.5Aug 25
Google Chrome: use after free
Critical9.6Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.