Content Security Policy Level 2

An evolution of the Content Security Policy specification, allowing developers to create a whitelist of sources of trusted content, and instructing the browser to only execute or render resources from those sources.


Established standard

Status in Chromium


Enabled by default in:

  • Chrome for desktop release 40
  • Chrome for Android release 40
  • Android WebView release 40
  • Opera release 27
  • Opera for Android release 27

Consensus & Standardization


Last updated on 2017-06-14