VYPR
Medium severity4.2NVD Advisory· Published Aug 18, 2026· Updated Aug 20, 2026

CVE-2026-76033

CVE-2026-76033

Description

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Affected products

4

Patches

Vulnerability mechanics

References

2

News mentions

4