Executive brief
A vulnerability in Google Chrome's graphics engine (ANGLE) could allow a malicious website to access data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of sensitive information across different browser tabs. Google has released an update to address this issue, and users should ensure their browser is updated to the latest version.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Almost Native Graphics Layer Engine (ANGLE) component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass cross-origin isolation and read data from other origins. This is a client-side attack requiring user interaction (visiting a malicious site). The vulnerability was addressed in Chrome version 150.0.7871.46.
Affected products
- Google Chrome Prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 150.0.7871.46 released for Windows
- 2026-07-01: advisory: NVD publication date