CVE-2026-78954: High Incorrect authorization in Extensions
Chromium: CVE-2026-78954 Incorrect authorization in Extensions
Other sources
Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade
Google Chrome / Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 152.0.7977.65
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-85043
- CVE-2026-102324
- CVE-2026-87499
- CVE-2026-85052
- CVE-2026-84324
- CVE-2026-103630
- CVE-2026-95372
- CVE-2026-95351
- CVE-2026-17657
- CVE-2026-91708
- CVE-2026-95339
- CVE-2026-79201
- CVE-2026-95310
- CVE-2026-95356
- CVE-2026-19173
- CVE-2026-91737
- CVE-2026-79218
- CVE-2026-84325
- CVE-2026-91722
- CVE-2026-91724
- CVE-2026-91721
- CVE-2026-79219
- CVE-2026-19137
- CVE-2026-19170
- CVE-2026-87647
- CVE-2026-91736
- CVE-2026-87514
- CVE-2026-91716
- CVE-2026-95313
- CVE-2026-91749
- CVE-2026-84357
- CVE-2026-85051
- CVE-2026-85053
- CVE-2026-87628
- CVE-2026-17666
- CVE-2026-79195
- CVE-2026-84349
- CVE-2026-79174
- CVE-2026-79187
- CVE-2026-79274
- CVE-2026-78952
- CVE-2026-79078
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must first compromise the Chrome renderer process. Exploitation then involves a crafted HTML page to bypass the web origin policy.
Which Chrome versions should be remediated?
Google Chrome versions prior to 152.0.7977.65 are affected. Update to 152.0.7977.65 or a later version.