Description
Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-04
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A security flaw in the Paint component of Google Chrome enables a remote attacker to craft an HTML page that circumvents the browser’s same‑origin policy. The inability to enforce the policy correctly means that a page served from one origin can read or manipulate resources from a different origin that the user should not have access to. This creates a confidentiality and integrity risk by potentially exposing sensitive data or allowing further malicious code execution. The vulnerability is categorized with Chromium security severity Medium.

Affected Systems

The defect exists in Google Chrome on all platforms with versions older than 149.0.7827.53. Users running any pre‑149.0.7827.53 build are affected; Chrome updates after that revision contain the fix.

Risk and Exploitability

The level of exploitation appears to involve only the delivery of a malicious HTML page rendered in the victim’s browser, indicating a local, in‑browser attack vector that requires the user to open the page. The Chromium severity is listed as Medium and no EPSS score is available, suggesting limited evidence of active exploitation. The vulnerability is not part of the CISA KEV catalog. Based on the description, the attacker would need to entice a user to load the crafted page, after which the same‑origin policy bypass could be leveraged to access or transmit protected resources.

Generated by OpenCVE AI on June 5, 2026 at 05:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 149.0.7827.53 or later
  • Check Chrome version via the About menu and download the latest stable release
  • If an upgrade is not immediately possible, disable the Paint feature or restrict JavaScript execution from untrusted origins

Generated by OpenCVE AI on June 5, 2026 at 05:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 05:30:00 +0000

Type Values Removed Values Added
Title Google Chrome Paint Same‑Origin Policy Bypass via Malicious HTML Page
Weaknesses CWE-1025
CWE-200

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:05:12.928Z

Reserved: 2026-06-04T17:06:57.379Z

Link: CVE-2026-11132

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-04T23:17:19.320

Modified: 2026-06-05T15:02:59.990

Link: CVE-2026-11132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T06:30:33Z

Weaknesses