Description
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome before 150.0.7871.47 contains a CSS parsing flaw that allows a remote attacker to craft an HTML page that bypasses the browser’s same‑origin policy, enabling the read or modification of data from a different origin that would normally be protected. This flaw is identified as CWE‑346. The vulnerability can lead to leakage of confidential information or alteration of web content.

Affected Systems

All users operating Google Chrome versions prior to 150.0.7871.47 are affected; the fix is delivered in that version and later releases.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% reflects a very low exploitation likelihood. The flaw is not listed in CISA’s KEV catalog. Exploitation requires a victim to open a malicious HTML page, likely through a web site or email, and would result in cross‑origin data exfiltration or manipulation if successful.

Generated by OpenCVE AI on August 2, 2026 at 00:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later to apply the CSS parsing patch identified as CWE‑346.
  • Enable automatic browser updates to receive security fixes as soon as they are issued.
  • Use network controls, such as firewalls or content filters, to block or quarantine traffic to domains that have been detected serving malicious or compromised web content.

Generated by OpenCVE AI on August 2, 2026 at 00:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Sun, 02 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title CSS Parsing Bypass Enabling Same Origin Policy Escalation in Google Chrome

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Same-Origin Policy Bypass via CSS Parsing Vulnerability in Google Chrome

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Same-Origin Policy Bypass via CSS Parsing Vulnerability in Google Chrome

Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via CSS Parsing Flaw in Google Chrome

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via CSS Parsing Flaw in Google Chrome

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS Parsing in Google Chrome

Sun, 12 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS Parsing in Google Chrome

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same Origin Policy Bypass Vulnerability

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same Origin Policy Bypass Vulnerability

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Allows Same-Origin Policy Bypass

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Allows Same-Origin Policy Bypass

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same-Origin Policy Bypass Prior to 150.0.7871.47

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same-Origin Policy Bypass Prior to 150.0.7871.47

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Enables Same-Origin Policy Bypass

Sat, 04 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Enables Same-Origin Policy Bypass

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title CSS Parsing Vulnerability Enables Same Origin Policy Bypass

Fri, 03 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title CSS Parsing Vulnerability Enables Same Origin Policy Bypass

Fri, 03 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Same Origin Policy Bypass via CSS Parsing Flaw

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Same Origin Policy Bypass via CSS Parsing Flaw

Thu, 02 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title CSS Parsing Flaw Enables Same Origin Policy Bypass in Google Chrome

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title CSS Parsing Flaw Enables Same Origin Policy Bypass in Google Chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Improper CSS Handling in Google Chrome
Weaknesses CWE-284

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Improper CSS Handling in Google Chrome
Weaknesses CWE-284

Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS in Chrome
Weaknesses CWE-601
CWE-79

Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS in Chrome
Weaknesses CWE-601
CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:16:34.383Z

Reserved: 2026-06-29T23:03:30.247Z

Link: CVE-2026-13838

cve-icon Vulnrichment

Updated: 2026-07-01T15:16:26.591Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T01:00:05Z

Weaknesses