Description
Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient policy enforcement in the Passwords module of Google Chrome prior to 150.0.7871.115 allows a remote attacker to bypass the Same‑Origin Policy with a crafted HTML page. The flaw is an input validation weakness identified as CWE‑20. The impact is that an attacker could gain access to resources normally protected by origin checks; the CVE text does not specify whether data can be read or modified, so the exact damage scope is not defined.

Affected Systems

All desktop builds of Google Chrome that run a version older than 150.0.7871.115 are affected. The CVE description does not explicitly state whether only the stable channel is impacted; the reference notes refer to Chrome updates prior to 150.0.7871.115. This includes Windows, macOS, and Linux platforms.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity from a CVSS perspective, although Chromium labels the issue as High, reflecting the policy‑bypass nature. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can deliver the malicious HTML through a hosted website or an embedded file that a user opens, but the description does not confirm whether additional local actions such as file‑system or network access are required. Based on the description, it is inferred that access to otherwise origin‑restricted content might be possible, though the extent is not explicitly described.

Generated by OpenCVE AI on July 24, 2026 at 08:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.115 or later.
  • Enable automatic updates to ensure receipt of future security fixes without manual intervention.
  • Exercise caution when accessing untrusted or suspicious websites and consider using a sandboxed browsing environment to isolate potentially malicious content.

Generated by OpenCVE AI on July 24, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Fri, 24 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Chrome Same-Origin Policy Bypass Through Passwords Module

Tue, 21 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome Same-Origin Policy Bypass Through Passwords Module

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Chrome Passwords Component

Mon, 13 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Chrome Passwords Component

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Insufficient Password Policy Enforcement Enables Same‑Origin Policy Bypass in Google Chrome

Sat, 11 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Insufficient Password Policy Enforcement Enables Same‑Origin Policy Bypass in Google Chrome

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Crafted HTML Page in Chrome Passwords
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via Crafted HTML Page in Chrome Passwords
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-09T10:33:06.056Z

Reserved: 2026-07-08T17:07:42.988Z

Link: CVE-2026-15124

cve-icon Vulnrichment

Updated: 2026-07-09T10:32:59.416Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T08:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation