Описание
Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| chromium | fixed | 146.0.7680.71-1 | package | |
| chromium | end-of-life | bullseye | package |
EPSS
Связанные уязвимости
An insufficient policy enforcement flaw was found in the ChromeDriver component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=478783560
Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2026-3934 Insufficient policy enforcement in ChromeDriver
Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
EPSS