Executive brief
Google Chrome, a widely used web browser, contained a security vulnerability in its resource loading component. If an attacker first compromises the browser's rendering process, they could use this flaw to steal sensitive data from other websites you have open. This could lead to the exposure of private information or login sessions from different web domains.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Loader component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass cross-origin isolation boundaries. By enticing a user to visit a specially crafted HTML page, the attacker can leak sensitive data from different origins. This vulnerability is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-04-08: disclosed: Reported to Chrome by Google researchers
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date