Executive brief
A security vulnerability in Google Chrome's Media Router component could allow a malicious website to bypass the browser's Same Origin Policy. This policy is a fundamental security boundary that prevents websites from interacting with data from other sites. If exploited, an attacker could potentially access sensitive information or perform unauthorized actions on other websites the user is logged into.
Technical details
An inappropriate implementation in the Media Router component of Google Chrome prior to version 151.0.7922.72 allowed a remote attacker to bypass the Same Origin Policy (SOP). The vulnerability is triggered when a user visits a specially crafted HTML page controlled by the attacker. By bypassing SOP, the attacker can potentially read data from or interact with other web origins that the user has active sessions with. This issue was assigned a Medium severity rating by the Chromium project. Users are advised to update to version 151.0.7922.72 or later to mitigate this risk.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date