Executive brief
A security vulnerability in Google Chrome's IndexedDB component could allow a malicious website to bypass security boundaries. IndexedDB is a system used by browsers to store large amounts of data locally. If exploited, an attacker who has already partially compromised the browser's rendering process could access or manipulate data belonging to other websites, violating the Same Origin Policy that normally keeps web data isolated.
Technical details
An improper input validation vulnerability (CWE-20) exists in the IndexedDB component of Google Chrome. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by providing specially crafted input. A successful exploit requires the attacker to have already compromised the renderer process. Once achieved, the attacker can use a crafted HTML page to access data across different origins, which is normally restricted by browser security controls. The issue is resolved in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE published to NVD.