Executive brief
A vulnerability in the Enterprise component of Google Chrome on Windows could allow a remote attacker to access data from other websites or applications. By tricking a user into opening a malicious file, the attacker could bypass security boundaries designed to keep information from different sources separate. This could lead to the unauthorized disclosure of sensitive user information.
Technical details
An inappropriate implementation in the Enterprise component of Google Chrome on Windows allowed for cross-origin data leakage. A remote attacker could exploit this by providing a malicious file that, when processed by the browser, bypasses Same-Origin Policy (SOP) or similar isolation boundaries. This vulnerability is specific to the Windows platform and was addressed in Chrome version 151.0.7922.72. The issue is tracked internally by Chromium as issue 496195854 and is classified with a 'Low' severity by the vendor.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72 for Windows
- 2026-07-30: disclosed