Executive brief
A vulnerability in Google Chrome's network component could allow a malicious website to access data from other websites you have open. This type of 'cross-origin' leak can potentially expose sensitive information to an attacker if a user visits a specially crafted webpage. Google has released an update to address this issue and recommends users update to the latest version of the browser.
Technical details
An inappropriate implementation vulnerability exists within the Network component of Google Chrome. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass certain cross-origin isolation policies and leak data from different origins. This issue is fixed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. The vulnerability is categorized by Chromium as Low severity.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google released the stable channel update for desktop.
- 2026-07-30: disclosed: NVD published the CVE record.