Executive brief
A vulnerability in the Google Chrome web browser could allow a malicious website to secretly access data from other websites you have open. By using a specially crafted web page, an attacker can exploit a flaw in how the browser handles page scrolling to leak sensitive information across different sites. This could lead to the exposure of private user data or session information. Users should update to the latest version of Chrome to protect their information.
Technical details
A side-channel information leakage vulnerability exists in the Scroll component of Google Chrome prior to version 150.0.7871.47. The flaw, classified as CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a specially crafted HTML page, the attacker can monitor side-channel signals related to scrolling behavior to infer and leak data from a different origin. This vulnerability was assigned a 'High' severity rating by the Chromium project. The issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2025-11-04: disclosed: Reported by Vsevolod Kokorin and Jorian Woltjer
- 2026-06-30: patched: Fixed in Chrome 150.0.7871.47 stable channel update
- 2026-06-30: advisory: NVD publication date