Executive brief
A security vulnerability exists in Google Chrome for Windows that could allow a malicious website to bypass the browser's Same Origin Policy. This policy is a fundamental security feature that prevents websites from accessing data belonging to other sites. If exploited, an attacker who has already partially compromised the browser's rendering process could potentially steal sensitive information, such as login credentials or personal data, from other websites the user has open.
Technical details
A Same Origin Policy (SOP) bypass vulnerability exists in the Media component of Google Chrome for Windows. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries under specific conditions. An attacker who has already achieved code execution within a compromised renderer process can leverage a specially crafted HTML page to bypass SOP. This allows the attacker to access data across different origins, potentially leading to information disclosure. The issue is resolved in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed