Executive brief
A vulnerability in Google Chrome's internal web interface could allow a remote attacker to access sensitive data from other websites or services. This occurs when the browser fails to properly verify information received over the network, potentially leading to the exposure of private user information. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebUI component of Google Chrome prior to version 150.0.7871.47. The flaw stems from insufficient validation of untrusted input, which allows a remote attacker to leak cross-origin data via malicious network traffic. While specific exploitation details are restricted, the vulnerability is classified by Chromium as Medium severity and typically involves a remote attacker inducing a user to interact with malicious content to bypass Same-Origin Policy (SOP) protections. The issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Google Chrome release announcement published.
- 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.