Executive brief
A security vulnerability exists in the Google Chrome web browser for Linux. An attacker who has already partially compromised the browser's internal processes could use this flaw to inject malicious scripts or HTML into other websites you visit. This could lead to unauthorized access to sensitive information or the hijacking of user sessions on various web platforms.
Technical details
This vulnerability is classified as an inappropriate implementation in the 'Views' component of Google Chrome on Linux. It allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Same-Origin Policy (SOP) protections. By utilizing a specially crafted HTML page, the attacker can perform Universal Cross-Site Scripting (UXSS), injecting arbitrary scripts or HTML into the context of other web origins. The vulnerability is addressed in Chrome version 149.0.7827.155. While CISA-ADP rates this as Medium (4.7), Chromium internally classifies the severity as High.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-30: other: Reported to Google
- 2026-06-16: patched: Stable channel update released
- 2026-06-17: advisory: NVD publication date