Executive brief
A vulnerability in Google Chrome's extension system could allow a malicious extension to steal data from other websites. To exploit this, an attacker must first trick a user into installing a specifically crafted extension. If successful, the attacker could gain access to sensitive information from other open tabs or web services that the user is logged into.
Technical details
An inappropriate implementation in the Extensions component of Google Chrome prior to version 151.0.7922.72 allowed for cross-origin data leakage. The vulnerability is triggered when a user installs a malicious, crafted Chrome Extension. This flaw enables the extension to bypass intended security boundaries and access data from origins other than its own. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux. Security engineers should ensure browsers are updated to version 151.0.7922.72 or later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date