Executive brief
Google Chrome is a web browser used to access the internet. A vulnerability in the Android version of the browser could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information if a user visits a specially crafted web page.
Technical details
An inappropriate implementation in the Input component of Google Chrome on Android allowed a remote attacker to leak cross-origin data. The vulnerability requires the attacker to have already compromised the renderer process. By enticing a user to visit a crafted HTML page, the attacker can bypass Same-Origin Policy (SOP) protections to access data from other origins. This issue is fixed in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched