Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76033

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 8.7

Описание

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome's handling of Cross-Origin Resource Sharing (CORS). A remote attacker, who has already compromised the browser's renderer process, could exploit this vulnerability by using a specially crafted HTML page. This could allow the attacker to bypass site isolation, a security feature designed to prevent malicious websites from accessing data from other websites, potentially leading to unauthorized data access.

Отчет

This Important flaw in chromium-browser allows a remote attacker to bypass site isolation after an initial compromise of the browser's renderer process. This could lead to unauthorized access to sensitive data from other websites, significantly undermining a core browser security boundary.

Дополнительная информация

Статус:

Important
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2518270chromium-browser: Google Chrome: Site isolation bypass due to inappropriate CORS implementation

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 1 месяца назад

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVSS3: 4.2
nvd
около 1 месяца назад

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

msrc
28 дней назад

Chromium: CVE-2026-76033 Inappropriate implementation in CORS

CVSS3: 4.2
debian
около 1 месяца назад

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7 ...

CVSS3: 4.2
github
около 1 месяца назад

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

8.7 High

CVSS3