Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 140.0.7339.80
A vulnerability in Google Chrome's Extensions component, present in versions prior to 140.0.7339.80, allowed remote attackers to bypass content security policies by using a specially crafted HTML page. This issue arose from inappropriate implementation within the Extensions framework.
Exploitation of this vulnerability could lead to unauthorized bypassing of content security policies, potentially allowing for malicious actions or the injection of harmful content through extensions.
Users can update to Google Chrome version 140.0.7339.80 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.