CVE-2026-93379
chrome: Incorrect Authorization (CVE-2026-93379)
mediumEPSS 0.3%
Description
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
googlechrome
153.0.8010.52fixed from 153.0.8010.52Metrics
Show all metrics
Severity
medium
53.38
no public PoC known
4.3
Published
2026-09-30 20:25 UTC
CWE-863
Weakness classes (CWE)
CWE-863Class
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-30 18:18 UTC· chrome-cve-admin@google.com
- Description: Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High) → Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
- Initial Analysis2026-09-21 11:09 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 153.0.8010.52
- Reference Type: Chrome: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html Types: Release Notes, Vendor Advisory
- Reference Type: Chrome: https://issues.chromium.org/issues/560039872 Types: Permissions Required
- CVE Modified2026-09-18 14:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- SSVC: {"id":"CVE-2026-93379","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-17 21:17 UTC· chrome-cve-admin@google.com
- Description: Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
- CWE: CWE-863
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93379.json">CVE-2026-93379</a>
- Reference: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html