Executive brief
A vulnerability in Google Chrome's networking component could allow a malicious website to access data from other websites you have open. This bypasses standard browser security boundaries that normally keep information from different sites separate. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the theft of sensitive personal or session information.
Technical details
A cross-origin data leak vulnerability exists in the Network component of Google Chrome. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries under specific conditions. A remote attacker can exploit this by hosting a malicious HTML page that, when rendered by a victim's browser, leverages the networking flaw to access data from a different origin. This bypasses Same-Origin Policy (SOP) protections. The issue is resolved in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed