Executive brief
A security issue in Google Chrome for Android could allow a malicious website to access data from other websites. This occurs when an attacker has already partially compromised the browser's internal processing system and uses a specially crafted webpage to bypass security boundaries. While the risk is considered low, it could lead to the unauthorized disclosure of sensitive information across different web origins.
Technical details
A vulnerability exists in the WebAuthentication component of Google Chrome for Android due to insufficient policy enforcement. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a malicious HTML page, the attacker can leak sensitive data across different origins. This issue is addressed in version 149.0.7827.53 and later. Google classifies this as a Low severity security issue.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-05: disclosed: CVE published