Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's extension system could allow a malicious website to access data from other websites that the user is currently visiting. This could lead to the unauthorized exposure of sensitive personal or account information if a user visits a specially crafted page while their browser is already in a partially compromised state.
Technical details
An insufficient policy enforcement vulnerability exists in the Extensions component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass cross-origin restrictions. By enticing a user to visit a crafted HTML page, the attacker can leak data across origins, potentially exposing sensitive information from other web contexts. This vulnerability is categorized as 'Low' severity by Chromium because it requires a pre-existing compromise of the renderer process as a prerequisite. The issue is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched