VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 149 of 209
  • CVE-2026-79213MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79211MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79205MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79199MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79190MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79178MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79174MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79143MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79141MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79137MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-79136MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79093MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79082MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79077MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79051MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79050MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79003MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78961MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78954MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78946MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)