Description
Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient policy enforcement in the HTML-in-Canvas feature of Google Chrome before version 150.0.7871.125 allows a remote attacker to create a crafted HTML page that bypasses the browser’s same-origin policy. This flaw exploits a weakness in policy enforcement (CWE‑346) and effectively permits access to data or resources that should be restricted, exposing sensitive information or enabling other unauthorized actions.

Affected Systems

Google Chrome releases earlier than 150.0.7871.125 are vulnerable; any user or organization running those versions is at risk until the update is applied.

Risk and Exploitability

The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, the CVSS score of 6.5 reflects a medium severity, and the nature of a same-origin policy bypass means that a determined attacker, once they deliver a crafted HTML page to the victim, could compromise the confidentiality and integrity of data presented within the canvas context. The likely attack vector is remote delivery of the malicious page via a website or compromised site.

Generated by OpenCVE AI on August 12, 2026 at 00:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.125 or later
  • Restrict canvas operations in custom or embedded instances by applying stricter policy controls
  • Validate and sanitize all HTML content rendered in canvas elements to ensure it originates only from trusted sources

Generated by OpenCVE AI on August 12, 2026 at 00:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chrome same-origin policy bypass via insecure HTML-in-Canvas chromium-browser: chromium-browser: Insufficient policy enforcement in HTML-in-Canvas
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}

threat_severity

Important


Tue, 28 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome same-origin policy bypass via insecure HTML-in-Canvas
Weaknesses CWE-285

Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass in Google Chrome Canvas Rendering
Weaknesses CWE-284

Wed, 22 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass in Google Chrome Canvas Rendering
Weaknesses CWE-284

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title HTML-in-Canvas Same-Origin Policy Bypass in Google Chrome
Weaknesses CWE-1140
CWE-285

Thu, 16 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title HTML-in-Canvas Same-Origin Policy Bypass in Google Chrome
Weaknesses CWE-1140
CWE-285

Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-15T15:22:09.181Z

Reserved: 2026-07-14T18:31:15.317Z

Link: CVE-2026-15768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-14T21:16:42.333

Modified: 2026-07-15T17:49:24.167

Link: CVE-2026-15768

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:52Z

Links: CVE-2026-15768 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:00:04Z

Weaknesses