Loading
Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Use CWE-284, Google vendor hub and Chrome product page to widen CVE-2026-6313 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-7363, CVE-2026-7361 and CVE-2026-7359 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.