Executive brief
A vulnerability in the Bluetooth component of Google Chrome could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data. Google has released an update to address this issue in Chrome version 150.0.7871.47.
Technical details
An information disclosure vulnerability exists in the Bluetooth component of Google Chrome due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to read sensitive information from the browser's process memory. This vulnerability is classified as 'Low' severity by Chromium and is fixed in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory