Executive brief
A vulnerability in Google Chrome's Document Object Model (DOM) implementation could allow a malicious website to bypass the Same-Origin Policy. This policy is a fundamental security boundary that prevents one website from reading data from another. If exploited, an attacker could potentially access sensitive information, such as login sessions or personal data, from other websites the user has open in their browser.
Technical details
A Same-Origin Policy (SOP) bypass vulnerability exists in the DOM component of Google Chrome. The flaw stems from an inappropriate implementation within the DOM handling logic, which can be triggered when a user visits a specially crafted HTML page. A remote attacker can exploit this to bypass security restrictions that normally isolate web content from different origins, potentially leading to unauthorized data access across browser tabs or frames. The vulnerability is addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD