Description
Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Google Chrome’s network layer allows a remote attacker to craft an HTML page that bypasses the browser’s content‑security policy. Because the policy is not enforced, scripts or resources that would normally be blocked can be loaded or executed, compromising the integrity of the displayed content. The weakness corresponds to CWE‑693, a protection mechanism failure.

Affected Systems

Google Chrome desktop releases earlier than version 150.0.7871.47 are affected. Systems running those versions and not yet updated are exposed to the risk.

Risk and Exploitability

The CVSS score is 4.3, indicating low overall severity. The EPSS score is below 1 %, reflecting a very low likelihood of current exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector is remote; an attacker must first entice a user to load a maliciously crafted web page, but no publicly available exploit code is documented. Because the bypass undermines CSP enforcement, it could enable further attacks such as injection of malicious scripts or loading of unauthorized resources, but the CVE description does not explicitly state that arbitrary code execution is achieved.

Generated by OpenCVE AI on July 15, 2026 at 23:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to apply the network policy enforcement fix.
  • Enable Chrome’s automatic update feature to receive future patches without manual intervention.
  • If an immediate upgrade is not possible, review the browser’s policy settings (e.g., via chrome://policy) to ensure that content‑security policy enforcement remains active and consider restricting loading of untrusted content.

Generated by OpenCVE AI on July 15, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Insufficient policy enforcement allows content security policy bypass via crafted HTML page

Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Insufficient policy enforcement allows content security policy bypass via crafted HTML page

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome CSP Bypass via Crafted Web Page

Thu, 09 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome CSP Bypass via Crafted Web Page

Wed, 08 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Google Chrome Content Security Policy Bypass via Crafted Web Page

Tue, 07 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Google Chrome Content Security Policy Bypass via Crafted Web Page

Mon, 06 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Network Policy Enforcement in Chrome

Mon, 06 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Network Policy Enforcement in Chrome

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Crafted Web Page in Google Chrome

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Crafted Web Page in Google Chrome

Sat, 04 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Crafted Web Page in Google Chrome

Sat, 04 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass via Crafted Web Page in Google Chrome

Fri, 03 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Insufficient Network Policy Enforcement Allows Content Security Policy By‑pass in Google Chrome

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Insufficient Network Policy Enforcement Allows Content Security Policy By‑pass in Google Chrome

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chrome Network Policy Flaw Allows Content Security Policy Bypass

Thu, 02 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome Network Policy Flaw Allows Content Security Policy Bypass

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Bypass of Content Security Policy via Crafted HTML Page in Google Chrome Prior to 150.0.7871.47
Weaknesses CWE-285
CWE-74

Wed, 01 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Bypass of Content Security Policy via Crafted HTML Page in Google Chrome Prior to 150.0.7871.47
Weaknesses CWE-285
CWE-74

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Policy Bypass Allows CSP Bypass via Crafted Page
Weaknesses CWE-270
CWE-285

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Network Policy Bypass Allows CSP Bypass via Crafted Page
Weaknesses CWE-270
CWE-285

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T12:44:16.422Z

Reserved: 2026-06-29T23:11:37.265Z

Link: CVE-2026-14076

cve-icon Vulnrichment

Updated: 2026-07-01T12:44:01.283Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:30:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure