CVE-2025-9866

Publication date

2025-09-03 16:17:48

Family

Chrome

State

PUBLISHED

Description

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)