Executive brief
A vulnerability in the Google Chrome web browser could allow a malicious website to bypass security boundaries. By tricking a user into visiting a specially crafted webpage, an attacker could execute unauthorized scripts or display fake content within the context of other websites. This could lead to the theft of sensitive information like login tokens or personal data from the affected sites.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Keyboard component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly isolate execution contexts when handling specific keyboard-related events or inputs. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP) and execute arbitrary JavaScript or inject HTML into any web domain currently open in the browser. This issue is resolved in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published by NVD.