Executive brief
Google Chrome's DevTools, a set of web developer tools built directly into the browser, contained a vulnerability that could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. This could lead to the unauthorized exposure of sensitive information across different web domains.
Technical details
A vulnerability exists in Google Chrome's DevTools component due to insufficient data validation. A remote attacker can exploit this by hosting a malicious HTML page and tricking a user into performing specific UI gestures. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak data from other origins. The vulnerability is addressed in Chrome version 150.0.7871.47 and later. This issue is categorized by Chromium as Low severity.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47