Executive brief
Google Chrome, a widely used web browser, contained a security flaw in its networking component. This vulnerability could allow a malicious website to bypass security boundaries and run unauthorized scripts or display fake content on other websites you visit. An attacker could use this to steal sensitive information or perform actions on your behalf without your knowledge.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Network component of Google Chrome due to an inappropriate implementation. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP) and execute arbitrary JavaScript or inject HTML into the context of other web origins. This issue is resolved in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched