Junglewise Threat Intelligence

CVE-2026-13935: Google Chrome side-channel information leakage in ComputePressure

CVE-2026-13935 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's ComputePressure component could allow a malicious website to observe sensitive data from other open websites or the user's system. By using a specially crafted web page, an attacker can exploit timing differences or other side channels to bypass standard security boundaries that normally keep website data separate. This could lead to the unauthorized disclosure of private information.

Technical details

A side-channel information leakage vulnerability exists in the ComputePressure API of Google Chrome. The flaw (CWE-1300) allows a remote attacker to bypass cross-origin isolation by observing side-channel data through a crafted HTML page. This could enable the extraction of sensitive information across different origins. The vulnerability is present in versions prior to 150.0.7871.47 and has been addressed in the stable channel update. No authentication or user interaction beyond visiting a malicious site is required for exploitation.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats