Executive brief
Google Chrome, a widely used web browser, was found to have a security flaw in its media handling component. This vulnerability could allow a malicious website to bypass security boundaries and access data from other websites you have open. While rated as low severity, it represents a potential privacy risk where sensitive information could be leaked to an unauthorized party.
Technical details
A side-channel information leakage vulnerability exists in the Media component of Google Chrome. The flaw, classified under CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a specially crafted HTML page, the attacker can exploit timing or other side-channel signals to extract data from a different origin. This vulnerability was addressed in Google Chrome version 151.0.7922.72. No authentication or special privileges are required beyond the ability to serve a malicious webpage to the victim.
Affected products
- Google Chrome Prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date