Description
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an incorrect implementation in the V8 JavaScript engine that permits a remote attacker to circumvent the same‑origin policy when loading a specially crafted HTML page. This flaw, classified as CWE‑346, effectively lets the attacker read or manipulate resources across origins, potentially exposing confidential data or executing unauthorized code.

Affected Systems

Google Chrome versions before 150.0.7871.125 are affected. The issue exists on all operating systems where Chrome includes the vulnerable V8 build, and affects users who have not upgraded to the patched stable channel release.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity. The EPSS score of < 1% indicates a very low risk of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to serve or lure a victim to a malicious HTML page, placing the attack vector in a web‑based context that depends on user interaction.

Generated by OpenCVE AI on July 31, 2026 at 04:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 150.0.7871.125 or later to remove the V8 flaw.
  • Enable automatic updates for Chrome to receive future security patches promptly.
  • Review and tighten the Content Security Policy settings of web applications to restrict cross‑origin script execution and mitigate potential bypasses.

Generated by OpenCVE AI on July 31, 2026 at 04:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via V8 in Google Chrome chromium-browser: chromium-browser: Insufficient policy enforcement in V8
References
Metrics threat_severity

None

threat_severity

Important


Sat, 25 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Same‑Origin Policy Bypass via V8 in Google Chrome

Fri, 17 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Chrome V8 Same‑Origin Policy Bypass via Crafted HTML

Thu, 16 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Chrome V8 Same‑Origin Policy Bypass via Crafted HTML

Wed, 15 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-15T15:44:12.137Z

Reserved: 2026-07-14T18:31:17.351Z

Link: CVE-2026-15775

cve-icon Vulnrichment

Updated: 2026-07-15T15:42:34.938Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:54Z

Links: CVE-2026-15775 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:00:05Z

Weaknesses