Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 138.0.7204.49
A vulnerability allowing remote attackers to bypass content security policy has been identified in Google Chrome. This issue arises from insufficient policy enforcement in the Loader component, affecting Chrome versions prior to 138.0.7204.49. The vulnerability can be exploited by crafting a specific HTML page.
Exploitation of this vulnerability allows for content security policy bypass, which could lead to the execution of malicious scripts or the loading of harmful resources that would typically be blocked by the policy.
Users can update to Google Chrome version 138.0.7204.49 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.