Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its Print Preview feature. An attacker who has already partially compromised the browser's internal processing could exploit this flaw to steal sensitive data from other websites you have open. This could lead to the unauthorized exposure of personal information or login sessions.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the Print Preview component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation policies. A precondition for this exploit is that the attacker must have already achieved code execution within a compromised renderer process. By utilizing a specially crafted HTML page, the attacker can then leak sensitive data across different origins. The issue was addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-25: disclosed: Reported by Google internal researchers
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory