Executive brief
A vulnerability in Google Chrome's networking component could allow a malicious website to capture data from other websites you have open. By tricking a user into visiting a specially crafted webpage, an attacker could bypass security boundaries to leak sensitive information across different origins. This could lead to the unauthorized disclosure of private user data or session information.
Technical details
A side-channel information leakage vulnerability exists in the Network component of Google Chrome. The flaw is categorized as CWE-1300 (Improper Protection of Physical Side Channels), which in this context allows a remote attacker to bypass Same-Origin Policy (SOP) protections. By inducing a user to visit a malicious HTML page, the attacker can leverage side-channel techniques to extract data from different origins. This vulnerability was addressed in Chrome version 151.0.7922.72. The Chromium team has classified this with a 'Low' security severity.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date