Executive brief
Google Chrome is a widely used web browser. A vulnerability in its 'Paint' component allows a malicious website to potentially see information from other websites you have open. This could lead to the unauthorized disclosure of sensitive data across different web origins if a user visits a specially crafted page.
Technical details
A side-channel information leakage vulnerability exists in the Paint component of Google Chrome. The flaw is categorized as CWE-1300 (Improper Protection of Physical Side Channels). By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit timing or rendering side channels to extract data from a different origin (cross-origin). This bypasses the Same-Origin Policy (SOP) to leak sensitive information. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory