Description
Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper handling of network traffic in Google Chrome before 150.0.7871.47 allowed an attacker positioned on a privileged network to inject or modify data in transit, circumventing the browser’s Content Security Policy. This bypass permits the loading or execution of scripts and resources that would normally be blocked, potentially allowing malicious code to run in the context of a web page and compromise information integrity or enable further exploitation.

Affected Systems

Google Chrome versions earlier than 150.0.7871.47 are affected on all desktop operating systems supported by the browser. No specific operating‑system restrictions were disclosed.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating medium severity. Its EPSS score is less than 1%, pointing to a low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Exploitation requires an attacker with privileged control over network traffic, so it is limited to environments where an adversary can intercept or inject data. While the potential impact of bypassing CSP can be significant—allowing script injection or the loading of unauthorized content— the realistic risk is moderate due to the low exploitability likelihood and the requirement for a privileged network position.

Generated by OpenCVE AI on July 1, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later
  • Restart the browser to ensure the updated binaries are active
  • In environments where immediate upgrade is not possible, restrict outbound traffic to known secure endpoints and enforce CSP policies through network‑level filtering or browser enterprise controls

Generated by OpenCVE AI on July 1, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Malicious Network Traffic in Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Component Enables Content Security Policy Bypass via Malicious Network Traffic
Weaknesses CWE-284
CWE-79

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome Network Component Enables Content Security Policy Bypass via Malicious Network Traffic
Weaknesses CWE-284
CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:18:31.002Z

Reserved: 2026-06-29T23:03:39.807Z

Link: CVE-2026-13876

cve-icon Vulnrichment

Updated: 2026-07-01T14:18:22.673Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T19:30:18Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure