Executive brief
Google Chrome, a widely used web browser, contained a security flaw in its Speech component. A remote attacker could use a specially crafted website to bypass security boundaries that normally prevent different websites from accessing each other's data. While rated as low severity, this could potentially allow a malicious site to interact with or access information from other open web pages.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the Speech component of Google Chrome. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP), which is a fundamental security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. The attack vector involves a victim visiting a malicious, specially crafted HTML page. Successful exploitation could allow the attacker to perform unauthorized cross-origin actions. The issue is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD publication date
- 2026-06-30: patched: Chrome Stable Channel Update released