Executive brief
A security vulnerability exists in Google Chrome's DevTools, a set of web developer tools built directly into the browser. An attacker who has already partially compromised the browser's rendering process could use this flaw to bypass security boundaries that normally prevent websites from accessing each other's data. This could lead to the unauthorized access of sensitive information from other open websites or user accounts.
Technical details
An insufficient validation of untrusted input vulnerability exists in the DevTools component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass the Same Origin Policy (SOP) via a specially crafted HTML page. By exploiting this weakness, an attacker can interact with or extract data from origins they should not have access to. The vulnerability is addressed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Stable channel update released for desktop
- 2026-06-04: disclosed: CVE published to NVD