Description
Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient policy enforcement in the Passwords module of Google Chrome before version 150.0.7871.115 allows a remote attacker to bypass the Same‑Origin Policy by serving a crafted HTML page. The flaw is an input validation weakness identified as CWE‑20. The result is that a malicious page can access resources that should be restricted by origin checks, potentially exposing sensitive data or enabling further interaction with the user’s browsing context.

Affected Systems

All users running a desktop build of Google Chrome older than version 150.0.7871.115 are potentially affected. The vulnerability is tied specifically to the Passwords component and does not relate to other product lines.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity according to the CVSS framework, but Chromium labels the issue as High because it represents a direct policy bypass. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. Attackers would need to lure a victim to a maliciously crafted page; no privileged code execution or local interaction is required beyond viewing the page. The risk is therefore limited to scenarios where a user visits an untrusted site or opens a malicious file that renders the page technique.

Generated by OpenCVE AI on July 31, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.115 or later.
  • Ensure automatic updates are enabled so future patches are received promptly.
  • Avoid visiting untrusted or suspicious sites and use Chrome’s Safe Browsing features to reduce exposure to malicious content.

Generated by OpenCVE AI on July 31, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Fri, 31 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Passwords Module in Google Chrome

Fri, 24 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Chrome Same-Origin Policy Bypass Through Passwords Module

Tue, 21 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome Same-Origin Policy Bypass Through Passwords Module

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Chrome Passwords Component

Mon, 13 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Chrome Passwords Component

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Insufficient Password Policy Enforcement Enables Same‑Origin Policy Bypass in Google Chrome

Sat, 11 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Insufficient Password Policy Enforcement Enables Same‑Origin Policy Bypass in Google Chrome

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Crafted HTML Page in Chrome Passwords
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Crafted HTML Page in Chrome Passwords
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-09T10:33:06.056Z

Reserved: 2026-07-08T17:07:42.988Z

Link: CVE-2026-15124

cve-icon Vulnrichment

Updated: 2026-07-09T10:32:59.416Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-08T23:16:53.547

Modified: 2026-07-09T17:50:17.520

Link: CVE-2026-15124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation