Junglewise Threat Intelligence

CVE-2026-13839: Google Chrome Same Origin Policy bypass in CSS

CVE-2026-13839 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's CSS engine could allow a malicious website to bypass the Same Origin Policy, which is a fundamental security boundary in web browsers. If exploited, an attacker could potentially access sensitive data from other websites you have open or perform actions on your behalf without authorization. This issue was resolved in Chrome version 150.0.7871.47.

Technical details

A vulnerability exists in the CSS implementation of Google Chrome prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that allows a remote attacker to bypass the Same Origin Policy (SOP) by enticing a user to visit a specially crafted HTML page. Successful exploitation could allow an attacker to read data across security domains or perform unauthorized actions in the context of other sites. Google has classified this as a High severity issue and released a fix in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats