Executive brief
A security vulnerability was identified in Google Chrome's Skia graphics engine, which is responsible for rendering 2D graphics and text. An attacker who has already partially compromised the browser's rendering process could exploit this flaw to steal sensitive data from other websites or tabs. This could lead to the exposure of private user information, such as login credentials or personal data, across different web domains.
Technical details
This vulnerability is classified as an 'Inappropriate implementation' within the Skia graphics component of Google Chrome. The flaw allows for cross-origin data leakage, effectively bypassing Same-Origin Policy (SOP) protections. An attacker must first achieve code execution within a compromised renderer process (a 'sandbox escape' or similar initial compromise is typically a precondition for this class of renderer-based leak). By enticing a user to visit a specially crafted HTML page, the attacker can then exfiltrate data belonging to other origins. The issue was addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-29: disclosed: Reported to Chromium by Google researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: advisory: NVD publication date