Google Chrome WebSockets Same-Origin Policy Bypass Vulnerability

Vulnerability

A vulnerability exists in Google Chrome in the WebSockets component, prior to version 147.0.7727.55. This issue allows a remote attacker, who has compromised the renderer process, to bypass the same-origin policy by exploiting insufficient validation of untrusted input. The vulnerability can be triggered through a crafted HTML page.

Impact

Exploitation of this vulnerability allows for a same-origin policy bypass, which could lead to unauthorized access or manipulation of data between different origins.

Remediation

Users can update to Google Chrome version 147.0.7727.55 or later to address this vulnerability.

Added: Apr 8, 2026, 11:12 PM
Updated: Apr 8, 2026, 11:12 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
3.6
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.