Executive brief
A vulnerability exists in Google Chrome's NoStatePrefetch feature, which is designed to speed up browsing by pre-loading certain page resources. A remote attacker could use a specially crafted website to bypass security boundaries and access data from other websites the user has open. This could lead to the unauthorized disclosure of sensitive user information across different web origins.
Technical details
A side-channel information leakage vulnerability was identified in the NoStatePrefetch component of Google Chrome. The flaw, classified as CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass cross-origin isolation policies. By enticing a user to visit a malicious HTML page, the attacker can leverage timing or other side-channel signals during the prefetching process to extract data from a different origin. This issue is resolved in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date