Description
Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient policy enforcement in the HTML‑in‑Canvas feature of Google Chrome before version 150.0.7871.125 allows a remote attacker to craft an HTML page that bypasses the browser’s same‑origin policy. This flaw effectively grants an attacker access to data or resources that should be protected, which could lead to theft of sensitive information or other unauthorized actions. The weakness represents an improper authorization flaw that undermines the fundamental security guarantees of web browsers.

Affected Systems

Google Chrome versions earlier than 150.0.7871.125 are affected. Any user or organization running these releases is vulnerable until a patch is applied.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known, commissioned exploit at this time. Nonetheless, the high severity rating and the nature of a same‑origin policy bypass mean that a determined attacker, once exploiting the flaw, could compromise the integrity of data viewed in the canvas context. The likely attack vector involves delivery of a crafted HTML page to the victim via a web page or compromised site.

Generated by OpenCVE AI on August 1, 2026 at 09:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.125 or later
  • Configure for canvas operations in any custom or embedded instances
  • Review and sanitize all HTML content that is rendered in canvas elements to ensure it originates only from trustworthy sources

Generated by OpenCVE AI on August 1, 2026 at 09:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chrome same-origin policy bypass via insecure HTML-in-Canvas chromium-browser: chromium-browser: Insufficient policy enforcement in HTML-in-Canvas
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}

threat_severity

Important


Tue, 28 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome same-origin policy bypass via insecure HTML-in-Canvas
Weaknesses CWE-285

Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass in Google Chrome Canvas Rendering
Weaknesses CWE-284

Wed, 22 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass in Google Chrome Canvas Rendering
Weaknesses CWE-284

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title HTML-in-Canvas Same-Origin Policy Bypass in Google Chrome
Weaknesses CWE-1140
CWE-285

Thu, 16 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title HTML-in-Canvas Same-Origin Policy Bypass in Google Chrome
Weaknesses CWE-1140
CWE-285

Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-15T15:22:09.181Z

Reserved: 2026-07-14T18:31:15.317Z

Link: CVE-2026-15768

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:52Z

Links: CVE-2026-15768 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses