Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its CSS implementation. This flaw could allow a malicious website to bypass security boundaries and execute unauthorized scripts or HTML in the context of other websites (Universal Cross-Site Scripting). An attacker could exploit this to steal sensitive user data, such as login credentials or session cookies, from other sites the user has open.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability existed in Google Chrome's CSS implementation due to an inappropriate implementation. By enticing a user to visit a specially crafted HTML page, a remote attacker could bypass the Same-Origin Policy (SOP) to execute arbitrary JavaScript or HTML in the context of any domain. This is classified by Chromium as a Medium severity issue. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date