Authorization Bypass in Google Chrome Affects Users
CVE-2026-91732

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91732?

A vulnerability in Google Chrome prior to version 153.0.8010.47 allows a remote attacker who has successfully compromised the renderer process to exploit missing authorization in AppManifest. This can be done by leveraging social engineering techniques to bypass the web origin policy via a specially crafted HTML page. Users should ensure their browser is updated to mitigate potential risks from this vulnerability.

Affected Version(s)

Chrome 153.0.8010.47

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.