Executive brief
A vulnerability in Google Chrome's Blink rendering engine could allow a malicious website to bypass the Same Origin Policy. This security boundary is designed to prevent websites from accessing data from other sites, such as your banking or email accounts. If exploited, an attacker could potentially read sensitive information from other open tabs or web sessions.
Technical details
An inappropriate implementation in the Blink rendering engine in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass the Same Origin Policy (SOP). By convincing a user to visit a specially crafted HTML page, an attacker could potentially access data across security origins. This is a logic-based vulnerability within the browser's core rendering component. The issue is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released
- 2026-07-30: disclosed: NVD publication date