Executive brief
Google Chrome is a web browser used to access internet content. A vulnerability in the way the browser handles page navigation could allow a malicious website to steal sensitive information from other websites you have open. This could lead to the exposure of private user data or login session information from different origins.
Technical details
A side-channel information leakage vulnerability exists in the Navigation component of Google Chrome. The flaw is categorized as CWE-1300 (Improper Protection of Physical Side Channels). A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak sensitive data from different origins. The issue is resolved in Google Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2023-12-18: other: Reported to vendor
- 2026-04-07: patched: Stable channel update released
- 2026-04-08: disclosed: Public advisory published