Sceawere
Vulnerability Detail
CVE-2026-95352UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Chrome DevTools Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 22h ago
- Vendor
- Product
- Chrome
- Attack Type
- Incorrect authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-29T18:17:28.197Z",
"pubdate": "2026-09-29T18:17:28.197Z",
"executiveSummary": "This vulnerability involves an incorrect authorization flaw within the Google Chrome DevTools interface, specifically impacting versions prior to 154.0.8037.57. The vulnerability manifests as a bypass of the Web Origin Policy, which is a fundamental security boundary in web browsers designed to prevent cross-site data leakage and unauthorized interactions.\nThe flaw allows a remote attacker to subvert security constraints by orchestrating a social engineering campaign that leads a user to interact with a malicious or crafted Chrome extension. Successful exploitation grants an attacker the capability to interact with the browser in ways that violate the intended origin isolation model.\nWhile the Chromium security severity is categorized as Low, the risk implications include the potential for unauthorized data access, cross-origin script execution, or unauthorized manipulation of the browser context. Exploitation requires user-assisted interaction via social engineering, making it a targeted threat vector. Organizations should prioritize updating Chrome to version 154.0.8037.57 or later to ensure the enforcement of proper authorization checks within the DevTools infrastructure.",
"technicalDetails": "The vulnerability resides within the authorization logic of the Chrome DevTools component. DevTools provides powerful diagnostic and debugging capabilities that require elevated privileges to inspect and modify web pages. Under normal operation, the browser enforces the Web Origin Policy to ensure that scripts from one origin cannot access or manipulate the DOM or storage of another origin. The vulnerability occurs because the authorization check mechanism within DevTools fails to correctly validate the origin of the request when invoked by a crafted Chrome extension.\nThe root cause is an improper authorization validation in the communication channel between extensions and the DevTools protocol. When a crafted extension interacts with the DevTools API, the validation process does not sufficiently verify whether the calling context is authorized to perform privileged operations across different origins. This effectively creates an 'authorization gap' where the security boundary usually imposed by the browser is bypassed by the extension's elevated capability.\nThe attack flow follows a structured path. First, the attacker must entice the user into installing or interacting with a malicious or specifically crafted Chrome extension, typically through social engineering tactics such as phishing or deceptive marketing. Once the extension is installed, the attacker utilizes the extension's ability to interface with the browser's internal APIs. When the target browser session is active, the crafted extension sends a series of requests to the DevTools interface. Because the DevTools component incorrectly handles the authorization handshake, it interprets these requests as legitimate, authorized operations originating from a trusted source. By bypassing the Web Origin Policy, the extension can interact with the DOM of the loaded web content, potentially exfiltrating sensitive information, session tokens, or performing unauthorized actions on behalf of the user within the context of the vulnerable site. This bypass is persistent as long as the malicious extension remains active and the browser version remains unpatched. The post-exploitation impact includes a total loss of origin-based isolation for the affected web content, allowing the attacker to bypass Same-Origin Policy (SOP) protections, which typically prevent cross-origin data theft or cross-site request forgery (CSRF) mitigation bypasses."
}