Executive brief
A vulnerability in Google Chrome's rendering engine could allow a malicious website to bypass Content Security Policy (CSP) restrictions. CSP is a security layer that helps detect and mitigate certain types of attacks, including data theft and site defacement. By tricking a user into visiting a specially crafted webpage, an attacker could bypass these protections, though the overall risk is considered low.
Technical details
An insufficient policy enforcement vulnerability exists in the Blink rendering engine of Google Chrome. The flaw allows a remote attacker to bypass Content Security Policy (CSP) via a specially crafted HTML page. This is a logic-based bypass where the browser fails to strictly enforce defined security headers, potentially allowing unauthorized script execution or resource loading that should have been blocked. The attack requires a user to navigate to a malicious URL (User Interaction). Google has addressed this in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-05: disclosed: NVD publication date