Executive brief
A security vulnerability in Google Chrome's MHTML handling could allow a malicious website to access data from other websites you have open. MHTML is a format used to save entire web pages into a single file. If a user visits a specially crafted page, an attacker could bypass security boundaries to leak sensitive information across different web origins.
Technical details
A policy bypass vulnerability exists in the MHTML component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections by enticing a user to open a specially crafted MHTML file or page. Successful exploitation enables the attacker to leak sensitive data from different origins (cross-origin data). The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Google classifies this as a Low severity issue.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date