Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in the browser's graphics processing component could allow a malicious website to bypass security boundaries and access data from other open websites or services. This could lead to the unauthorized exposure of sensitive user information or session data.
Technical details
A side-channel information leakage vulnerability exists in the GPU component of Google Chrome for Android. The flaw, classified as CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a specially crafted HTML page, the attacker can exploit hardware-level side channels to infer and leak data belonging to a different origin. This vulnerability was addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed