Executive brief
A vulnerability in the Google Chrome web browser could allow a malicious website to bypass security boundaries that normally prevent different sites from accessing each other's data. By tricking a user into visiting a specially crafted webpage, an attacker could potentially access sensitive information from other open websites or services. This could lead to the unauthorized exposure of user data or session information.
Technical details
A vulnerability exists in the Paint component of Google Chrome due to insufficient policy enforcement. A remote attacker can exploit this by hosting a specially crafted HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass the Same Origin Policy (SOP), which is a fundamental security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. This could lead to unauthorized access to sensitive data across different domains. The issue is fixed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published in NVD.