CORS Misconfiguration in Google Chrome Affects Web Security
CVE-2026-102320

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102320?

In Google Chrome versions prior to 154.0.8037.92, a critical misconfiguration in the Cross-Origin Resource Sharing (CORS) middleware allows unauthorized access. An attacker who gains control over the renderer process can exploit this vulnerability by delivering a specially crafted HTML page. This manipulation permits the bypassing of web origin policies, posing a significant risk to user data and application security. Users are urged to update to the latest versions to mitigate this security threat.

Affected Version(s)

Chrome 154.0.8037.92

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.