Executive brief
A vulnerability in the Linux version of Google Chrome's editing component could allow a malicious website to access data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different browser tabs or origins. Google has released an update to address this issue.
Technical details
A cross-origin data leak vulnerability exists in the Editing component of Google Chrome for Linux. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries during certain editing operations. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass Same-Origin Policy (SOP) protections and read data from other origins. This issue is resolved in Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google released the stable channel update for desktop.
- 2026-07-30: disclosed: CVE published in the NVD.