Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its Blink rendering engine. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access sensitive data from other websites the user has open. This could lead to the unauthorized exposure of personal information or login sessions.
Technical details
A vulnerability classified as an inappropriate implementation exists within the Blink rendering engine of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by enticing a user to visit a maliciously crafted HTML page. Successful exploitation enables the attacker to leak data across origins, which is a violation of the Same-Origin Policy. The issue is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Google has assigned this a 'Low' severity rating.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for desktop.
- 2026-07-30: disclosed: NVD publication date.