Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its networking component. This flaw could allow a remote attacker to execute malicious scripts or display unauthorized content on a user's screen when they visit a specially crafted website. If exploited, this could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user across different websites.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Network component of Google Chrome due to an inappropriate implementation. The flaw allows a remote attacker to bypass the Same-Origin Policy (SOP) by enticing a user to visit a malicious, specially crafted HTML page. Successful exploitation enables the attacker to execute arbitrary JavaScript or inject HTML content into the context of any website the user is currently visiting. This issue was addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date