Executive brief
A security vulnerability exists in Google Chrome's Isolated Web Apps feature. This flaw could allow a malicious website to bypass security restrictions (Content Security Policy) that are intended to prevent unauthorized scripts or content from running. If exploited, an attacker could potentially perform unauthorized actions within the context of the web application, though it requires a user to visit a specially crafted web page.
Technical details
An insufficient policy enforcement vulnerability exists in the Isolated Web Apps (IWA) component of Google Chrome. The flaw allows a remote attacker to bypass Content Security Policy (CSP) protections by enticing a user to visit a specially crafted HTML page. This bypass occurs because the browser fails to strictly enforce defined security policies within the IWA environment. Successful exploitation could allow for the execution of unauthorized web content or scripts that should have been blocked by the application's security headers. The issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory