Executive brief
A vulnerability in Google Chrome's graphics processing component could allow a malicious website to access data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of sensitive information across different browser tabs. Google has released an update to address this issue.
Technical details
A vulnerability classified as 'Uninitialized Use' (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak sensitive data from other origins. The issue is resolved in Google Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: advisory