Executive brief
A security vulnerability exists in Google Chrome for Mac that could allow a malicious website to access data from other open websites or services. To exploit this, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. If successful, this could lead to the unauthorized exposure of sensitive user information across different web domains.
Technical details
A vulnerability in the DataTransfer implementation of Google Chrome for macOS allowed for cross-origin data leakage. The flaw stems from insufficient isolation or validation during data transfer operations (such as drag-and-drop or copy-paste actions). A remote attacker could exploit this by hosting a malicious HTML page and inducing a user to perform specific UI gestures, thereby bypassing Same-Origin Policy (SOP) protections to access data from other origins. The issue is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Google Chrome release announcement published.
- 2026-06-30: patched: Fixed in version 150.0.7871.47