Junglewise Threat Intelligence

CVE-2026-13944: Google Chrome DataTransfer cross-origin data leak on Mac

CVE-2026-13944 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Mac that could allow a malicious website to access data from other open websites or services. To exploit this, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. If successful, this could lead to the unauthorized exposure of sensitive user information across different web domains.

Technical details

A vulnerability in the DataTransfer implementation of Google Chrome for macOS allowed for cross-origin data leakage. The flaw stems from insufficient isolation or validation during data transfer operations (such as drag-and-drop or copy-paste actions). A remote attacker could exploit this by hosting a malicious HTML page and inducing a user to perform specific UI gestures, thereby bypassing Same-Origin Policy (SOP) protections to access data from other origins. The issue is addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Google Chrome release announcement published.
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats