Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's permissions component could allow a malicious website to access data from other websites that the user has open. This could lead to the unauthorized disclosure of sensitive information across different web origins.
Technical details
A vulnerability classified as an 'Inappropriate Implementation' exists in the Permissions component of Google Chrome prior to version 149.0.7827.53. The flaw is associated with a race condition (CWE-362) involving concurrent execution using shared resources with improper synchronization. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, potentially allowing the attacker to bypass cross-origin isolation and leak sensitive data from other origins. The issue is resolved in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE published in NVD.