Описание
Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | code not present |
| esm-apps/noble | not-affected | code not present |
| esm-apps/resolute | not-affected | code not present |
| jammy | not-affected | code not present |
| noble | not-affected | code not present |
| resolute | not-affected | code not present |
| upstream | released |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Chromium CVE-2026-87550: Improper encoding or escaping of output in CSS
Improper encoding or escaping of output in CSS in Google Chrome prior ...
Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
EPSS
4.3 Medium
CVSS3