Description
Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper handling of network traffic in Google Chrome before 150.0.7871.47 allowed an attacker positioned on a privileged network to inject or modify data in transit, bypassing the browser’s Content Security Policy. This weakness permits the loading or execution of scripts and resources that would normally be blocked, potentially allowing malicious code to run in the context of a Web page and threaten information integrity or enable further exploitation. This vulnerability corresponds to CWE‑693.

Affected Systems

Google Chrome versions earlier than 150.0.7871.47 are affected. The CVE does not specify operating system restrictions.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating medium severity. Its EPSS score is less than 1%, pointing to a low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Exploitation requires an attacker with privileged control over network traffic, limiting it to environments where an adversary can intercept or inject data. While the potential impact of bypassing CSP—allowing script injection or loading of unauthorized content—is significant, the realistic risk is moderate due to the low exploitability likelihood and the necessity of a privileged network position.

Generated by OpenCVE AI on July 21, 2026 at 16:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later
  • Restart the browser to ensure the updated binaries are active
  • In environments where immediate upgrade is not possible, restrict outbound traffic to known secure endpoints and enforce CSP policies through network‑level filtering or browser enterprise controls

Generated by OpenCVE AI on July 21, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chrome Network Traffic CSP Bypass Vulnerability

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Network Traffic CSP Bypass Vulnerability

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome Network Traffic CSP Bypass in Versions Before 150.0.7871.47

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome Network Traffic CSP Bypass in Versions Before 150.0.7871.47

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Content Security Policy Bypass via Network Traffic

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chrome Content Security Policy Bypass via Network Traffic

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Google Chrome

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Google Chrome

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Handling Allows CSP Bypass by Privileged Network Actors

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Handling Allows CSP Bypass by Privileged Network Actors

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Network Traffic Manipulation in Google Chrome

Sun, 05 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Network Traffic Manipulation in Google Chrome

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Network CSP Bypass via Malicious Traffic

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome Network CSP Bypass via Malicious Traffic

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title CSP Bypass via Malicious Network Traffic in Google Chrome

Fri, 03 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title CSP Bypass via Malicious Network Traffic in Google Chrome

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Google Chrome

Thu, 02 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Google Chrome

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Chrome

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Component Enables Content Security Policy Bypass via Malicious Network Traffic
Weaknesses CWE-284
CWE-79

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome Network Component Enables Content Security Policy Bypass via Malicious Network Traffic
Weaknesses CWE-284
CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:18:31.002Z

Reserved: 2026-06-29T23:03:39.807Z

Link: CVE-2026-13876

cve-icon Vulnrichment

Updated: 2026-07-01T14:18:22.673Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:00:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure