AI analysis
Google Chrome before 154.0.8037.92 contains a missing authorization check (CWE-862) in its CORS implementation, allowing a bypass of the web origin policy (same-origin protections) via a crafted HTML page. Exploitation requires the attacker to have already compromised the renderer process, so this is primarily a second-stage flaw to be chained with a separate renderer bug rather than a standalone attack. A successful chain would let the attacker break out of origin-based isolation and access data or resources from web origins that should be protected. All users running Chrome versions older than 154.0.8037.92 are affected, and the issue was fixed in the Chrome 154 stable update that resolved 32 security flaws. Chromium rates the severity Medium; there is no public PoC, no known exploitation, and it is not in the CISA KEV catalog.
What to do: Update Chrome to 154.0.8037.92 or later immediately (verify at chrome://settings/help), and have enterprise admins confirm managed auto-update policies have completed rollout and check for stalled clients. Because exploitation requires a prior renderer compromise, ensure other renderer vulnerabilities are also patched promptly in the same update cycle. Users of Chromium-derived browsers (Edge, Brave, Opera, Vivaldi) should apply their vendors' updates once the corresponding Chromium 154 fix ships.
Affected
| Google Chrome | < 154.0.8037.92 |
Estimated exposure
mass≈3 billion users (Chrome's global install base across desktop and mobile) — The flawed CORS code ships in every Chrome build prior to 154.0.8037.92, and Chrome's global user base is on the order of 3 billion, so virtually all unpatched Chrome installations are exposed to the vulnerable code path.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.