Executive brief
A vulnerability in Google Chrome's CSS implementation could allow a malicious website to leak sensitive information from other websites you have open. By tricking a user into visiting a specially crafted webpage, an attacker could bypass security boundaries to access data that should normally be protected. This could lead to the unauthorized exposure of personal or session-related information from different web domains.
Technical details
An inappropriate implementation vulnerability exists in the CSS component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit this, an attacker must entice a user to visit a maliciously crafted HTML page. Successful exploitation enables the attacker to read data from other origins, potentially exposing sensitive user information or session tokens. The issue is addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.