Sceawere

Vulnerability Detail

CVE-2026-78946UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome Select Origin Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Incorrect authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-25T21:17:50.523Z",
  "pubdate": "2026-08-25T21:17:50.523Z",
  "executiveSummary": "This vulnerability involves an incorrect authorization flaw within the Select component of Google Chrome, specifically identified prior to version 152.0.7977.65.\nThe flaw allows a remote, unauthenticated attacker to circumvent the web origin policy, which is a fundamental security mechanism designed to isolate content from different domains.\nBy leveraging a specially crafted HTML page, an attacker can trick the browser into performing unauthorized actions that violate cross-origin boundaries.\nThe Chromium project has classified the severity of this vulnerability as 'Low'.\nSuccessful exploitation could lead to unauthorized data access or cross-site scripting scenarios, depending on the context of the bypass.\nThe primary risk implication is the potential erosion of the browser's sandbox environment, enabling malicious actors to interact with sensitive origins that should otherwise be protected from external scripts.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper authorization check within the Select form element implementation in the Chromium rendering engine.\nThe Select element failed to properly validate the origin context when managing user interactions or state changes, permitting a breach of the Same-Origin Policy (SOP).\nThe exploit flow begins with a remote attacker hosting a malicious HTML page. When a target user navigates to this page, the attacker uses the crafted markup to manipulate the Select element in a manner that bypasses existing origin-based security checks.\nSpecifically, the vulnerability allows the attacker to trigger behaviors that should be restricted to the scope of the target origin, effectively forcing the browser to treat cross-origin requests as if they originated from a trusted context.\nBecause the Select component manages UI-driven state transitions, the flaw potentially allows for the exfiltration of metadata or interaction with restricted domains that share an integrated environment with the malicious page.\nThis is a client-side vulnerability that requires no authentication or elevated privileges from the attacker; the requirement is solely the user's interaction with the attacker-controlled HTML content.\nThe vulnerability affects Google Chrome versions prior to 152.0.7977.65. The lack of robust authorization enforcement during Select element event handling creates a path for bypassing the browser's internal security perimeter.\nUpon successful exploitation, an attacker could potentially gain unauthorized read access to information that is supposed to be siloed by origin, or potentially manipulate application state within the affected origin's DOM.\nThe impact is contained within the context of the browser instance, as the vulnerability does not grant host-level code execution, but it effectively undermines the integrity of the browser's origin isolation model."
}
CVE-2026-78946: Chrome Select Origin Bypass (MEDIUM Severity, CVSS: 4.3) - Sceawere