Executive brief
A security issue in Google Chrome for Android could allow a malicious website to access data from other websites. This occurs due to a flaw in how the browser's user interface handles certain web pages, potentially leading to the exposure of sensitive user information across different sites. Users are advised to update their browser to the latest version to prevent this unauthorized data access.
Technical details
A vulnerability classified as an inappropriate implementation in the UI component of Google Chrome on Android exists in versions prior to 149.0.7827.53. The flaw allows a remote attacker to bypass cross-origin isolation policies. By enticing a user to visit a specially crafted HTML page, the attacker can trigger a data leak of information belonging to a different origin. This is a network-based attack that requires user interaction (visiting the malicious site). The issue has been addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-05: disclosed: CVE published