Executive brief
Google Chrome is a widely used web browser for accessing the internet. A security flaw in its networking component could allow a malicious website to bypass the 'Same Origin Policy,' which is a fundamental security rule that prevents one website from reading data from another. If exploited, an attacker could potentially access sensitive information from other websites you have open in your browser.
Technical details
This vulnerability is classified as a Same Origin Policy (SOP) bypass due to insufficient policy enforcement within Google Chrome's Network stack. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass security boundaries that normally isolate web content from different origins, potentially leading to unauthorized data access. The issue was addressed in Google Chrome version 150.0.7871.47. The Chromium project assigned this a 'Low' severity rating.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory