Description
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome before version 150.0.7871.47 contains an implementation flaw in CSS handling that lets a remote attacker construct a crafted HTML page to bypass the browser’s same‑origin policy. The resulting weakness can allow the attacker to read or modify content from another origin that normally would be protected, potentially leading to loss of confidentiality or integrity of web data.

Affected Systems

All users running Google Chrome versions older than 150.0.7871.47 are impacted; the vendor’s update to that version includes the fix for the flaw.

Risk and Exploitability

The CVSS score is 6.5 and the EPSS score is less than 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the delivery of a malicious HTML page to a victim through the web; no publicly available exploit is currently known, but the potential for cross‑origin data exfiltration or manipulation means remediation is recommended.

Generated by OpenCVE AI on July 16, 2026 at 12:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to 150.0.7871.47 or a newer release to apply the CSS parsing patch identified as CWE-346.
  • Enable automatic updates so that the browser receives the latest security fixes as soon as they are released.
  • Configure network defenses, such as firewalls or proxies, to block traffic to domains that serve malicious content capable of exploiting this same‑origin policy bypass.

Generated by OpenCVE AI on July 16, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via CSS Parsing Flaw in Google Chrome

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS Parsing in Google Chrome

Sun, 12 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS Parsing in Google Chrome

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same Origin Policy Bypass Vulnerability

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same Origin Policy Bypass Vulnerability

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Allows Same-Origin Policy Bypass

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Allows Same-Origin Policy Bypass

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same-Origin Policy Bypass Prior to 150.0.7871.47

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Same-Origin Policy Bypass Prior to 150.0.7871.47

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Enables Same-Origin Policy Bypass

Sat, 04 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Parsing Vulnerability Enables Same-Origin Policy Bypass

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title CSS Parsing Vulnerability Enables Same Origin Policy Bypass

Fri, 03 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title CSS Parsing Vulnerability Enables Same Origin Policy Bypass

Fri, 03 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Same Origin Policy Bypass via CSS Parsing Flaw

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Same Origin Policy Bypass via CSS Parsing Flaw

Thu, 02 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title CSS Parsing Flaw Enables Same Origin Policy Bypass in Google Chrome

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title CSS Parsing Flaw Enables Same Origin Policy Bypass in Google Chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Improper CSS Handling in Google Chrome
Weaknesses CWE-284

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Improper CSS Handling in Google Chrome
Weaknesses CWE-284

Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS in Chrome
Weaknesses CWE-601
CWE-79

Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via CSS in Chrome
Weaknesses CWE-601
CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:16:34.383Z

Reserved: 2026-06-29T23:03:30.247Z

Link: CVE-2026-13838

cve-icon Vulnrichment

Updated: 2026-07-01T15:16:26.591Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:45:05Z

Weaknesses