SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78947

MEDIUM · CVSS 6.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in Google Chrome prior to version 152.0.7977.65 allows remote attackers to exploit incomplete cleanup in Chromium, enabling them to bypass web origin policy through a maliciously crafted Chrome extension. This issue poses a low security risk primarily through social engineering tactics. Users and organizations utilizing affected versions of Chrome should prioritize updating to mitigate potential exploitation.

CVE
CVE-2026-78947
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%
Chrome

Original NVD Description

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)

Related CVEs

Other vulnerabilities affecting the same vendor(s)