Executive brief
A vulnerability in Google Chrome's CSS implementation could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker could execute unauthorized scripts or inject malicious content into other websites the user is visiting. This could lead to the theft of sensitive information, such as login credentials or personal data, from those other sites.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's CSS engine due to an inappropriate implementation. The flaw allows a remote attacker to bypass the Same-Origin Policy (SOP) by enticing a user to visit a malicious HTML page. By exploiting this weakness, the attacker can execute arbitrary JavaScript or inject HTML content into the context of any website currently open in the browser. This vulnerability was addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date