Executive brief
A vulnerability in the Clipboard component of Google Chrome for Android could allow a malicious website to access data from other websites. By tricking a user into visiting a specially crafted web page, an attacker could potentially leak sensitive information that should be protected by the browser's security boundaries. This issue primarily impacts the privacy of user data handled within the mobile browser.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Clipboard component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input, which can be exploited by a local attacker (via a malicious web page) to bypass cross-origin protections. By utilizing a crafted HTML page, an attacker can leak sensitive data across origins. The vulnerability is addressed in version 151.0.7922.72 and later. Chromium developers have assigned this a 'Medium' severity rating.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date