Executive brief
Google Chrome is a widely used web browser. A security flaw in its developer tools (DevTools) could allow a malicious website to bypass the browser's security boundaries. This could potentially allow an attacker to access sensitive information from other websites you have open, compromising user privacy and data security.
Technical details
A vulnerability exists in Google Chrome's DevTools component due to insufficient policy enforcement. A remote attacker can exploit this by tricking a user into visiting a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP), which is a fundamental security mechanism that prevents websites from interacting with data from other domains. This could lead to unauthorized access to sensitive data across different origins. The issue is resolved in Chrome version 149.0.7827.115.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-27: disclosed: Reported to Google internally
- 2026-06-11: patched: Stable channel update released
- 2026-06-11: advisory: NVD publication date