Executive brief
A vulnerability in Google Chrome's Content Security Policy (CSP) could allow a malicious website to bypass security restrictions. CSP is a safety layer that helps detect and mitigate certain types of attacks, such as data theft and site defacement. By tricking a user into visiting a specially crafted webpage, an attacker could circumvent these protections to execute unauthorized actions or access restricted data within the browser.
Technical details
A policy bypass vulnerability exists in the Content Security Policy (CSP) implementation of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass defined CSP directives by enticing a user to visit a specially crafted HTML page. Successful exploitation could allow the attacker to circumvent security controls intended to prevent cross-site scripting (XSS) or unauthorized resource loading. The vulnerability is classified as Low severity by Chromium and has been addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in version 149.0.7827.53
- 2026-06-05: disclosed: NVD publication date