High chrome Logic Error

Overview

High
Severity
CVSS
No
Exploited ITW
Embargoed
Fix Status
ImpactInsufficient policy enforcement in Canvas
DescriptionInsufficient policy enforcement in Canvas
ComponentCanvas
Bug ClassLogic Error
Tracker514609778
CISA KEVNot listed
CreditedBinglin Song
Disclosed2026-06-30

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.