Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its CSS implementation. A remote attacker could exploit this by tricking a user into visiting a specially crafted website, allowing the attacker to inject and execute malicious scripts or HTML within the context of other websites. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive information from other open web pages.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability existed in Google Chrome's CSS implementation due to an inappropriate implementation. By enticing a user to load a malicious HTML page, a remote attacker could bypass Same-Origin Policy (SOP) protections to execute arbitrary JavaScript or HTML in the context of other origins. The vulnerability is categorized by Chromium as 'Low' severity. The issue was addressed in Google Chrome version 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Google Chrome release announcement published.
- 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.