Executive brief
Google Chrome is a widely used web browser. A vulnerability in its 'Paint' component could allow a malicious website to access data from other websites you have open or are logged into. This could lead to the unauthorized disclosure of sensitive information across different web domains.
Technical details
An inappropriate implementation vulnerability exists in the Paint component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak data from different origins. The vulnerability is fixed in version 151.0.7922.72 and later. Chromium developers have assigned this a severity of Medium.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date