Executive brief
Google Chrome is a widely used web browser. A vulnerability in its reporting and network error logging components could allow a malicious website to access data from other websites you have visited. This type of information leak can compromise user privacy by exposing sensitive data across different web domains.
Technical details
A vulnerability exists in the Reporting and Network Error Logging (NEL) implementation of Google Chrome. The flaw is categorized as an inappropriate implementation that fails to properly enforce cross-origin boundaries. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which then triggers the leak of sensitive data from other origins. This bypasses the Same-Origin Policy (SOP) protections intended to keep data from different sites isolated. The issue is resolved in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date