Executive brief
Google Chrome, a widely used web browser, contained a security flaw in how it handles data storage permissions between different websites. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially allowing the attacker to access information from other websites that should have been kept private. While the risk is considered low, users should update to the latest version of Chrome to ensure their browsing data remains secure.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the StorageAccessAPI component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries through a specially crafted HTML page. By exploiting this weakness, an attacker can potentially leak sensitive data from a different origin than the one the user is currently visiting. The vulnerability is present in versions prior to 150.0.7871.47 and has been addressed in the stable channel update for Windows, Mac, and Linux. No authentication is required for exploitation, though it does require the victim to navigate to an attacker-controlled site.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Chrome Release blog published the vulnerability details.
- 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47 and later.