Description
Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insufficient policy enforcement in the ViewTransitions API of Google Chrome allows a remote attacker to leak cross‑origin data by loading a specially crafted HTML page. The flaw manifests as both CWE‑368 (Race Conditions) and CWE‑942 (URL‑based Unrestricted Read Access), and the Chromium security severity is rated high, indicating that sensitive information could be exposed that belongs to a different origin.

Affected Systems

Google Chrome versions prior to 148.0.7778.168 on all supported operating systems are impacted. The flaw is tied to the ViewTransitions feature, which is enabled by default in these releases.

Risk and Exploitability

The exploit requires no special privileges and is browser‑based, meaning a malicious website can include a crafted page to trigger the ViewTransitions policy bypass. The CVSS score is 4.3. The EPSS score is < 1 % (a very low but non‑zero likelihood of exploitation in the wild). The flaw is currently not listed in the CISA KEV catalog. Given the moderate severity rating and the remote nature of the attack vector, the risk to users is significant until the vulnerability is patched.

Generated by OpenCVE AI on May 15, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.168 or later.
  • If an immediate upgrade is not feasible, disable the ViewTransitions API via chrome://flags or a similar configuration until a patch is available.
  • Apply a strict Content Security Policy that blocks cross‑origin transitions until the issue is resolved.
  • Monitor Google's security advisories for any further updates or patches.

Generated by OpenCVE AI on May 15, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6273-1 chromium security update
History

Fri, 15 May 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-942
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Fri, 15 May 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 15 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via ViewTransitions Policy Bypass in Google Chrome chromium-browser: chromium-browser: Insufficient policy enforcement in ViewTransitions
Weaknesses CWE-368
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

threat_severity

Important


Thu, 14 May 2026 22:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via ViewTransitions Policy Bypass in Google Chrome
First Time appeared Google
Google chrome
Weaknesses CWE-200
Vendors & Products Google
Google chrome

Thu, 14 May 2026 20:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-15T13:47:09.476Z

Reserved: 2026-05-14T05:40:17.034Z

Link: CVE-2026-8537

cve-icon Vulnrichment

Updated: 2026-05-15T13:47:04.954Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-14T20:17:14.560

Modified: 2026-05-15T15:16:54.817

Link: CVE-2026-8537

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-14T19:52:21Z

Links: CVE-2026-8537 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-15T17:15:04Z

Weaknesses