Executive brief
A vulnerability in the Enterprise component of Google Chrome could allow a remote attacker to access sensitive information from the browser's memory. To exploit this, an attacker would need to trick a user into visiting a malicious website and performing specific interactions or gestures within the browser interface. While the risk is considered low, successful exploitation could lead to the exposure of data handled by the browser process.
Technical details
This vulnerability is classified as an inappropriate implementation within the Enterprise component of Google Chrome. The flaw allows for side-channel information leakage from process memory. An attacker can exploit this by hosting a specially crafted HTML page and convincing a user to perform specific UI gestures. The vulnerability requires user interaction and is triggered via the network vector. Google has addressed this issue in Chrome version 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Google Chrome release announcement published.
- 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.