Executive brief
A vulnerability in Google Chrome's CSS engine could allow a malicious website to extract sensitive information from the browser's memory. By tricking a user into visiting a specially crafted webpage, an attacker could use technical side-channels to observe data they should not have access to. This could lead to the exposure of private user data or browsing information.
Technical details
A side-channel information leakage vulnerability exists in the CSS component of Google Chrome. The flaw is categorized under CWE-1300 (Improper Protection of Physical Side Channels) and stems from how the browser handles CSS rendering or timing. A remote attacker can exploit this by hosting a malicious HTML page; when a user visits the page, the attacker can use side-channel techniques to read sensitive data from the browser's process memory. This vulnerability was addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Google Chrome release announcement published.
- 2026-06-30: patched: Fixed in version 150.0.7871.47.