Executive brief
A security vulnerability in Google Chrome's Performance APIs could allow a malicious website to access data from other websites you have open. This type of flaw breaks the browser's security boundaries, potentially exposing sensitive information from different web sessions. Users should update their browser to the latest version to prevent this unauthorized data access.
Technical details
A cross-origin data leak vulnerability exists in Google Chrome's PerformanceAPIs due to an inappropriate implementation. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this flaw to bypass Same-Origin Policy (SOP) protections and access data from other origins. The vulnerability is categorized by Chromium as Medium severity. It was addressed in Chrome version 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched