Description
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome versions prior to 149.0.7827.53 have an insecure permissions implementation that lets a remote attacker craft an HTML page to bypass the browser’s content security policy. The flaw originates from improper enforcement of CSP constraints, identified as a weakness that can allow arbitrary script execution or data exfiltration when a malicious page is opened. Though Chromium rates the severity as low, the capability to execute untrusted code within the browser’s context elevates the risk to the confidentiality, integrity, and availability of the affected system.

Affected Systems

All stable channel releases of Google Chrome older than 149.0.7827.53 on desktop platforms are affected. The vulnerability applies to every device that runs these browser versions, regardless of operating system, because it is tied to the core rendering engine’s permission handling.

Risk and Exploitability

No publicly available exploit is known, and the EPSS score is not available, so the exact likelihood of exploitation remains unclear. The flaw can be triggered by a crafted HTML page delivered via a web server or even a local file, implying that a remote or local attacker could use social‑engineering or phishing to induce a user to open the page. The CVE is not listed in the CISA KEV catalog, indicating that it is not a known high‑volume active exploit, but mitigations should still be applied promptly to eliminate the vulnerability since the attack path is straightforward once the malicious page is visited.

Generated by OpenCVE AI on June 5, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or later, which includes the fixed permissions handling.
  • Configure Chrome Enterprise policies to enforce content security policy enforcement strictly, particularly for internal or untrusted web content.
  • Educate users to avoid opening unknown or suspicious HTML pages and to verify the security settings of installed browsers.

Generated by OpenCVE AI on June 5, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 00:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Crafted HTML Page in Google Chrome
Weaknesses CWE-1142

Thu, 04 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:06:08.167Z

Reserved: 2026-06-04T17:11:07.706Z

Link: CVE-2026-11260

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-05T00:17:02.730

Modified: 2026-06-05T00:17:02.730

Link: CVE-2026-11260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T01:30:25Z

Weaknesses