CVE-2026-6313
LOW
NVD
CVSS Score
3.1
Severity
LOW
Published
Apr 15, 2026
Vendor
unknown
Description
Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)