Junglewise Threat Intelligence

CVE-2026-13959: Google Chrome same origin policy bypass in Blink

CVE-2026-13959 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security vulnerability in its Blink rendering engine. An attacker could exploit this by tricking a user into visiting a specially crafted website, allowing the attacker to bypass the Same Origin Policy. This could lead to the unauthorized access of sensitive data from other websites the user has open, potentially compromising personal accounts or private information.

Technical details

A vulnerability exists in the Blink rendering engine of Google Chrome due to improper input validation (CWE-20). A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass the Same Origin Policy (SOP), which is a fundamental security mechanism that prevents scripts on one page from accessing data on another page from a different origin. This issue was addressed in Chrome version 150.0.7871.47. Chromium developers classified this as a Medium severity issue.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats