A vulnerability labeled as problematic has been found in Google Chrome. This affects an unknown part of the component Headless. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.

This vulnerability is tracked as CVE-2026-17883. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.