Executive brief
A vulnerability in Google Chrome's data transfer component could allow a malicious website to access information from other websites you have open. This bypasses standard security boundaries designed to keep data from different sites separate. While rated as low severity, it could lead to the unauthorized disclosure of sensitive user information if a victim visits a specially crafted webpage.
Technical details
A cross-origin data leak vulnerability exists in the DataTransfer implementation of Google Chrome. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries during data transfer operations (such as drag-and-drop or copy-paste actions). A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page, potentially allowing the attacker to read data belonging to a different origin. This issue is resolved in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date