CVE-2026-79201: Medium Improper access control in Workers
Chromium: CVE-2026-79201 Improper access control in Workers
Other sources
Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade
Google Chrome / Chromiumto a version that resolves this vulnerability.Fixed in 152.0.7977.65
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-85043
- CVE-2026-102324
- CVE-2026-87499
- CVE-2026-85052
- CVE-2026-84324
- CVE-2026-103630
- CVE-2026-95372
- CVE-2026-95351
- CVE-2026-17657
- CVE-2026-91708
- CVE-2026-95339
- CVE-2026-95310
- CVE-2026-95356
- CVE-2026-19173
- CVE-2026-91737
- CVE-2026-79218
- CVE-2026-84325
- CVE-2026-91722
- CVE-2026-91724
- CVE-2026-91721
- CVE-2026-79219
- CVE-2026-19137
- CVE-2026-19170
- CVE-2026-87647
- CVE-2026-91736
- CVE-2026-87514
- CVE-2026-91716
- CVE-2026-95313
- CVE-2026-91749
- CVE-2026-84357
- CVE-2026-85051
- CVE-2026-85053
- CVE-2026-87628
- CVE-2026-17666
- CVE-2026-79195
- CVE-2026-84349
- CVE-2026-78954
- CVE-2026-79174
- CVE-2026-79187
- CVE-2026-79274
- CVE-2026-78952
- CVE-2026-79078
Frequently Asked Questions
Which Chrome versions need to be updated?
Google Chrome versions prior to 152.0.7977.65 are affected. Update to 152.0.7977.65 or a later version.
What does an attacker need to exploit this issue?
The attacker needs to induce a user to load a crafted HTML page remotely. The issue allows bypass of the web origin policy through improper access control in Workers.