Junglewise Threat Intelligence

CVE-2026-13838: Google Chrome Same Origin Policy bypass in CSS

CVE-2026-13838 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its CSS implementation could allow a malicious website to bypass the Same Origin Policy, which is a fundamental security barrier that prevents websites from accessing each other's data. If exploited, this could lead to the unauthorized access or theft of sensitive information from other websites the user is logged into.

Technical details

A Same Origin Policy (SOP) bypass vulnerability exists in the CSS implementation of Google Chrome. The flaw stems from an inappropriate implementation that allows a remote attacker to circumvent security boundaries via a specially crafted HTML page. By enticing a user to visit a malicious site, an attacker can leverage this bypass to access data across origins, potentially leading to information disclosure or unauthorized actions in the context of other web sessions. This issue was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats