---
id: CVE-2026-79251
title: >-
  chromium-browser: Google Chrome: Web origin policy bypass via improper input
  validation (CVE-2026-79251)
summary: >-
  A flaw was found in Google Chrome. Improper input validation in the Network
  component allows a remote attacker to potentially bypass the web origin
  policy. This can be achieved by enticing a user to visit a specially crafted
  HTML page. The…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cvssSource: vendor
cwe:
  - CWE-20
vendor: Red Hat
product: Chrome
affected:
  - Chrome >= 152.0.7977.65 < 152.0.7977.65
published: '2026-08-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T04:49:47+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79251.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79251.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-79251'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-79251'
  - url: >-
      https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
  - url: 'https://issues.chromium.org/issues/513392351'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00281
epssPercentile: 0.18365
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-27T19:38:56.322477Z'
scores:
  vendor: 6.5
  adp: 4.3
ingestedAt: '2026-09-17T23:31:20.806Z'
---

## Overview

A flaw was found in Google Chrome. Improper input validation in the Network component allows a remote attacker to potentially bypass the web origin policy. This can be achieved by enticing a user to visit a specially crafted HTML page. The web origin policy is a critical security mechanism that prevents malicious websites from interacting with content from other domains.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79251.json)

**chromium-browser: Google Chrome: Web origin policy bypass via improper input validation**. Released 2026-08-25, updated 2026-09-25.

Not affected:

- All currently supported Red Hat products

## Remediation

Refer to the advisory for fix availability.
