Upstream information

CVE-2026-91732 at MITRE

Description

Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

SUSE information

Overall state of this security issue: New

This issue is currently rated as having critical severity.

SUSE Bugzilla entry: 1280687 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Wed Sep 16 13:10:23 2026
CVE page last modified: Wed Sep 16 13:10:23 2026