Improper Authorization in Google Chrome Affects Web Origin Policy
CVE-2026-102330

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102330?

A vulnerability in Google Chrome prior to version 154.0.8037.92 permits attackers to exploit incorrect authorization within the SiteIsolation feature. By compromising the renderer process, an attacker can bypass web origin policies through a specially crafted HTML page, leading to potential security risks and unauthorized access to sensitive information.

Affected Version(s)

Chrome 154.0.8037.92

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.