Executive brief
A security vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites you have open. This occurs through the browser's sharing feature when a user visits a specially crafted web page. An attacker who has already partially compromised the browser's internal processing could use this to leak sensitive information across different sites.
Technical details
This vulnerability is classified as an inappropriate implementation within the Sharing component of Google Chrome on Android. The flaw allows a remote attacker who has already compromised the renderer process to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a malicious HTML page, the attacker can leak cross-origin data. The issue is addressed in Google Chrome version 150.0.7871.47. The vulnerability requires a pre-existing compromise of the renderer process as a precondition for the data leak.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched