Google Chrome Same Origin Policy Bypass Vulnerability in Navigations

Vulnerability

A vulnerability in Google Chrome's navigation component, present in versions prior to 135.0.7049.52, allowed remote attackers to bypass the same origin policy. This was achieved by convincing users to perform specific UI gestures while interacting with a crafted HTML page.

Impact

Exploitation of this vulnerability could lead to unauthorized access or manipulation of content from different origins, potentially allowing for cross-site scripting or other cross-origin attacks.

Remediation

Users can update to Google Chrome version 135.0.7049.52 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.