Executive brief
A security vulnerability in Google Chrome's StorageAccessAPI could allow a malicious website to access data from other websites. This occurs if an attacker has already partially compromised the browser's rendering process, enabling them to bypass privacy protections. An exploit could lead to the unauthorized leakage of sensitive user information across different web domains.
Technical details
This vulnerability is classified as insufficient policy enforcement (CWE-20) within the StorageAccessAPI component of Google Chrome. The flaw allows a remote attacker to leak cross-origin data, provided they have already achieved a compromise of the renderer process. By utilizing a specially crafted HTML page, the attacker can bypass intended security boundaries that normally restrict data access between different origins. The issue was addressed in Google Chrome version 150.0.7871.47. The attack requires the victim to visit a malicious page and assumes a pre-existing renderer compromise as a precondition.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory