Executive brief
A vulnerability in Google Chrome's CSS handling could allow a malicious website to bypass security policies. If a user visits a specially crafted webpage, an attacker could potentially leak sensitive data from other websites the user is currently logged into. This could lead to the unauthorized exposure of private user information across different web domains.
Technical details
A policy bypass vulnerability exists in the CSS implementation of Google Chrome. The flaw allows a remote attacker to bypass cross-origin restrictions by enticing a user to visit a maliciously crafted HTML page. By exploiting this issue, the attacker can perform a side-channel attack to leak data from a different origin, violating the Same-Origin Policy (SOP). The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux. Chromium developers have classified this as a Low severity issue.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date