Executive brief
A vulnerability in Google Chrome's data transfer handling could allow a malicious website to access information from other open websites or the user's system. To succeed, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. This could lead to the unauthorized disclosure of sensitive user data across different web domains.
Technical details
An inappropriate implementation vulnerability exists in the DataTransfer component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation policies by inducing a user to perform specific UI gestures (such as drag-and-drop or clipboard actions) on a malicious HTML page. Successful exploitation enables the attacker to leak sensitive data from different origins. The issue is addressed in Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: advisory