Executive brief
A security vulnerability exists in Google Chrome on Windows that could allow a malicious website to access data from other websites you have open. This occurs due to a flaw in Dawn, a component used for graphics processing. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of sensitive personal or session information.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Dawn component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass cross-origin isolation and read data from other origins. This vulnerability was reported by Google researchers and is addressed in Chrome version 149.0.7827.103. Exploitation requires the victim to navigate to a malicious website, but does not require prior authentication.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-17: disclosed: Reported by Google researchers
- 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date