Executive brief
A vulnerability in Google Chrome's Enterprise component could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted web page, potentially exposing private data or internal browser details. Users should update to the latest version of Chrome to protect their information.
Technical details
An inappropriate implementation vulnerability exists in the Enterprise component of Google Chrome prior to version 150.0.7871.47. The flaw allows a remote attacker to perform an information disclosure attack by enticing a user to visit a specially crafted HTML page. Successful exploitation enables the attacker to read potentially sensitive information from the browser's process memory. This is classified by Chromium as High severity. The issue is resolved in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-15: disclosed: Reported by Google internal researchers
- 2026-06-30: patched: Fixed in Stable Channel Update 150.0.7871.47
- 2026-06-30: advisory