Executive brief
Google Chrome is a widely used web browser. A security flaw in how the browser handles site permissions could allow a malicious website to bypass security restrictions known as Content Security Policy (CSP). This could potentially allow an attacker to access information or perform actions that the browser's security rules are intended to block.
Technical details
A vulnerability exists in the Permissions component of Google Chrome due to an inappropriate implementation. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass Content Security Policy (CSP) restrictions, which are designed to prevent unauthorized script execution and data exfiltration. The issue is addressed in Chrome version 149.0.7827.53. Google classifies this as a Low severity issue.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-05: disclosed: CVE published in NVD