Executive brief
Google Chrome is a widely used web browser. A security vulnerability in the browser's media handling component could allow a remote attacker to access sensitive data from other websites or services the user is currently logged into. This type of attack typically requires the user to visit a specially crafted malicious website and could lead to the unauthorized disclosure of personal information or session data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome for Windows. The flaw allows a remote attacker who has already compromised the renderer process to bypass cross-origin resource sharing (CORS) protections. By enticing a user to visit a malicious HTML page, the attacker can leak sensitive data from different origins. This vulnerability was addressed in Google Chrome version 151.0.7922.72 for Windows.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-03: disclosed: Reported by Google internal researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date