Executive brief
Google Chrome, a widely used web browser, was found to have a security flaw in its media handling component. This vulnerability could allow a malicious website to bypass security boundaries and access data from other websites you have open. In practice, this could lead to the unauthorized disclosure of sensitive information from different web sessions.
Technical details
A side-channel information leakage vulnerability exists in the Media component of Google Chrome. The flaw, classified as CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a specially crafted HTML page, an attacker can exploit this side channel to extract cross-origin data. The vulnerability was reported by Google internal researchers and is addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-28: disclosed: Reported by Google researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: advisory: NVD publication date