Google Chrome ChromeDriver Same Origin Policy Bypass Vulnerability

Vulnerability

A vulnerability in ChromeDriver for Google Chrome, prior to version 146.0.7680.71, allowed remote attackers to bypass the same origin policy by using a crafted HTML page. This issue arose from insufficient policy enforcement.

Impact

Exploitation of this vulnerability could lead to unauthorized bypassing of the same origin policy, potentially allowing for cross-origin attacks or data theft.

Remediation

Users can update to Google Chrome version 146.0.7680.71 or later to address this vulnerability.

Added: Mar 11, 2026, 10:25 PM
Updated: Mar 11, 2026, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
5.8
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.