Sceawere
Vulnerability Detail
CVE-2026-95287UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Google Chrome Navigation Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 22h ago
- Vendor
- Product
- Chrome
- Attack Type
- Missing authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-29T18:17:20.393Z",
"pubdate": "2026-09-29T18:17:20.393Z",
"executiveSummary": "A critical vulnerability categorized as a missing authorization flaw exists within the navigation architecture of Google Chrome prior to version 154.0.8037.57.\nThis vulnerability allows a remote attacker who has successfully compromised the renderer process to circumvent established site isolation security boundaries.\nBy leveraging a specifically crafted HTML document, an attacker can perform unauthorized navigation operations, potentially accessing data or resources belonging to other origins.\nThe vulnerability is rated as Medium severity due to the requirement of an initial compromise of the renderer process, which typically necessitates the exploitation of a secondary vulnerability (such as a memory corruption flaw).\nIf successfully exploited, the attacker can break out of the constrained renderer sandbox environment to influence cross-origin navigation, undermining the core principle of Site Isolation.\nThe vulnerability affects all Google Chrome deployments running versions prior to 154.0.8037.57.\nOrganizations are advised to prioritize the application of the latest security patches to mitigate risks associated with renderer process exploitation.",
"technicalDetails": "The vulnerability stems from insufficient authorization checks within the navigation request processing logic in Google Chrome's browser process. Site Isolation is a critical security architecture in Chromium designed to place documents from different sites into separate renderer processes. This architectural choice ensures that the browser enforces a security boundary, preventing a malicious site from accessing sensitive data (such as cookies, tokens, or local storage) associated with another site.\nThe root cause of this vulnerability lies in the navigation handler failing to adequately validate the authorization state of the requesting entity when transitioning between navigation states. When a renderer process is compromised—for instance, via a separate exploit chain involving heap spray or ROP (Return-Oriented Programming) to gain code execution—the attacker typically remains restricted by the renderer's sandbox, which limits their access to system resources and cross-origin data.\nThe attack flow commences with an attacker hosting a crafted HTML page designed to trigger the flaw. When a victim loads this page, the compromised renderer attempts to initiate a navigation request to a target origin. Normally, the browser process would scrutinize this request to ensure the renderer has the authority to navigate to the specified location or interact with cross-origin content.\nHowever, due to the missing authorization check, the navigation logic permits the request, allowing the attacker to bypass the Site Isolation guarantees. By manipulating navigation parameters within the crafted HTML document, the attacker forces the browser process to perform actions on behalf of the attacker, effectively 'confusing' the browser into accessing restricted domains or bypassing same-origin policy restrictions.\nExploitation allows the attacker to move beyond the boundaries of the compromised renderer. The post-exploitation impact includes the ability to perform cross-origin information disclosure or to conduct further unauthorized actions that would otherwise be blocked by the Site Isolation policy. Because this vulnerability involves the browser's navigation internals, it fundamentally undermines the trust model the browser relies upon to isolate disparate web origins. The exploitation is strictly post-renderer compromise, meaning the attacker must already possess the capability to execute code in the context of a renderer process before they can trigger the navigation bypass. The attack surface is exposed to any remote attacker capable of serving malicious content that forces the navigation logic into an insecure state."
}