Executive brief
A vulnerability in Google Chrome's favicon handling could allow a malicious website to leak information from other websites you have visited. By tricking a user into visiting a specially crafted webpage, an attacker could potentially bypass security boundaries designed to keep data from different sites separate. This could lead to a minor loss of privacy regarding a user's browsing activity across different domains.
Technical details
A cross-origin data leak vulnerability exists in the Favicons component of Google Chrome. The flaw is categorized as an improper protection of physical side channels (CWE-1300), where an inappropriate implementation allows a remote attacker to bypass Same-Origin Policy (SOP) restrictions. By inducing a user to visit a malicious HTML page, the attacker can exploit this side channel to exfiltrate data across origins. The issue is resolved in Google Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date