Junglewise Threat Intelligence

CVE-2026-18019: Google Chrome side-channel information leakage in Media

CVE-2026-18019 · Severity: info · Published 2026-07-30

Executive brief

Google Chrome, a widely used web browser, was found to have a security flaw in its media handling component. This vulnerability could allow a malicious website to bypass security boundaries and access data from other websites you have open. While rated as low severity, it represents a potential privacy risk where sensitive information could be leaked to an unauthorized party.

Technical details

A side-channel information leakage vulnerability exists in the Media component of Google Chrome. The flaw, classified under CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a specially crafted HTML page, the attacker can exploit timing or other side-channel signals to extract data from a different origin. This vulnerability was addressed in Google Chrome version 151.0.7922.72. No authentication or special privileges are required beyond the ability to serve a malicious webpage to the victim.

Affected products

  • Google Chrome Prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats