Executive brief
A vulnerability in Google Chrome's rendering component could allow a malicious website to access data from other websites you have open. This bypasses standard browser security boundaries that normally keep data from different sites isolated. An attacker would need to trick a user into visiting a specially crafted webpage to exploit this flaw.
Technical details
An inappropriate implementation vulnerability exists in the Paint component of Google Chrome. By leveraging a specially crafted HTML page, a remote attacker can bypass cross-origin isolation policies to leak sensitive data from different origins. The attack requires user interaction, specifically enticing a victim to visit a malicious website. This issue is addressed in Google Chrome version 149.0.7827.53 and later. The vulnerability is categorized by Chromium as Medium severity.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.