Description
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-06-17
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who convinces a user to install a malicious extension to bypass the browser’s same‑origin policy, enabling the attacker to read or modify content from web origins that the user did not consent to. The weakness is classified as CWE‑20, an input validation issue.

Affected Systems

Google Chrome browsers built before the 149.0.7827.155 release are affected, across all desktop platforms supported by Chrome. The issue applies to every user who installs a malicious extension before upgrading to the patched version.

Risk and Exploitability

The CVSS score of 4.2 reflects moderate severity, while the EPSS score of less than 1% indicates a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must persuade a user to install the malicious extension, and the exploit can only be performed while the user is actively using Chrome. This limits practical risk to environments where users install third‑party extensions and the browser remains unpatched beyond 149.0.7827.155.

Generated by OpenCVE AI on June 17, 2026 at 18:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.155 or newer to receive the vendor patch
  • Configure enterprise policy or Chrome Management to block or audit the installation of third‑party extensions
  • Educate users to verify extension permissions and source before installation

Generated by OpenCVE AI on June 17, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Jun 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-17T10:56:40.032Z

Reserved: 2026-06-16T19:38:30.107Z

Link: CVE-2026-12456

cve-icon Vulnrichment

Updated: 2026-06-17T10:56:34.004Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T07:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation