Executive brief
A vulnerability in Google Chrome's CSS implementation could allow a malicious website to leak data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially compromising the privacy of information from different origins. Google has released an update to address this issue in Chrome version 150.0.7871.47 and later.
Technical details
A cross-origin data leak vulnerability exists in Google Chrome's CSS engine due to an inappropriate implementation. By enticing a user to visit a malicious website, a remote attacker can leverage crafted HTML and CSS to bypass Same-Origin Policy (SOP) restrictions and extract information from other origins. This is classified by Chromium as a Medium severity issue. The vulnerability is resolved in Google Chrome version 150.0.7871.47 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched