Executive brief
A vulnerability in Google Chrome's Developer Tools (DevTools) could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into visiting a specially crafted webpage and performing specific mouse or keyboard actions. This could lead to the unauthorized disclosure of sensitive information across different web domains.
Technical details
A vulnerability classified as an inappropriate implementation exists in the DevTools component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation policies and leak data from different origins. Exploitation requires the attacker to host a malicious HTML page and successfully convince a user to perform specific UI gestures (such as drag-and-drop or specific click sequences) that interact with the DevTools interface. This issue is addressed in Chrome version 150.0.7871.47 and later. The Chromium project assigned this a Medium severity rating.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched