Executive brief
A vulnerability in Google Chrome's SurfaceCapture component could allow a malicious website to access data from other websites you have open. This bypasses standard browser security boundaries that normally keep data from different sites isolated. While rated as low severity, it could lead to the unauthorized disclosure of information if a user visits a specially crafted webpage.
Technical details
An inappropriate implementation vulnerability exists in the SurfaceCapture component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin resource sharing (CORS) or similar isolation policies to leak data from different origins. The vulnerability is present in versions prior to 151.0.7922.72 and has been assigned a 'Low' severity rating by the Chromium project.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google released the stable channel update fixing the issue.
- 2026-07-30: disclosed: NVD published the CVE record.