Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin p…
High CVSS 8.1
Summary
Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html Release Notes
- https://issues.chromium.org/issues/511062248 Exploit
Timeline
- nvd_ingest NVD