Description
Insufficient validation of untrusted input in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an insufficient validation of untrusted input within Blink in Google Chrome before version 150.0.7871.47. This weakness, identified as CWE-20, enables a remote attacker to bypass the browser's same‑origin policy by serving a specially crafted HTML page. The primary impact is that the policy, which isolates web content from different origins, can be circumvented, potentially undermining the browser's security guarantees.

Affected Systems

The vulnerability affects Google Chrome browsers running any version earlier than 150.0.7871.47. No other products or vendors are known to be impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3 and an EPSS score of less than 1%, indicating low severity and a low likelihood of exploitation, and it is not listed in CISA KEV. Exploitation would involve a victim loading a specially crafted HTML page, a common scenario in phishing or drive‑by attacks. The likely attack vector is a web page hosted on an attacker‑controlled site that a user visits. This flaw bypasses the browser’s same‑origin policy, potentially undermining the isolation between web origins.

Generated by OpenCVE AI on July 17, 2026 at 14:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome 150.0.7871.47 or newer
  • Apply or enforce a strict Content‑Security‑Policy that restricts cross‑origin resource loading for unusual navigation or scripting patterns originating from untrusted sources
  • Enable Chrome’s built‑in security features such as Safe Browsing and Pop‑Up blocking to reduce exposure to malicious HTML pages

Generated by OpenCVE AI on July 17, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Custom HTML in Chrome

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Blink Allows Same Origin Policy Bypass

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Blink Allows Same Origin Policy Bypass

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Insufficient Input Validation in Blink

Sun, 12 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Insufficient Input Validation in Blink

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Blink Input Validation in Google Chrome

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Blink Input Validation in Google Chrome

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Blink Input Validation in Google Chrome

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Blink Input Validation in Google Chrome

Mon, 06 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Blink Allows Same Origin Policy Bypass in Google Chrome

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Blink Allows Same Origin Policy Bypass in Google Chrome

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Blink Input Validation Allows Same-Origin Policy Bypass in Google Chrome

Sat, 04 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Blink Input Validation Allows Same-Origin Policy Bypass in Google Chrome

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Insufficient Input Validation in Chrome Blink

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Insufficient Input Validation in Chrome Blink

Fri, 03 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass in Google Chrome via Blink Input Validation Flaw

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass in Google Chrome via Blink Input Validation Flaw

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Remote Same Origin Policy Bypass via Untrusted Input in Blink

Wed, 01 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Same Origin Policy Bypass via Untrusted Input in Blink

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T14:17:59.672Z

Reserved: 2026-06-29T23:04:01.967Z

Link: CVE-2026-13959

cve-icon Vulnrichment

Updated: 2026-07-02T14:12:48.690Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation