Executive brief
Google Chrome includes APIs for measuring web page performance that are accessible to JavaScript running on web pages. A vulnerability in these PerformanceAPIs allowed attackers to extract sensitive cross-origin data by crafting malicious HTML pages, potentially exposing user information from other websites. This affects Chrome users prior to version 152.0.7977.65.
Technical details
An observable discrepancy in Chrome's PerformanceAPIs (likely a timing side-channel or state-exposure vulnerability) permitted attackers to infer or retrieve cross-origin data via crafted HTML pages. The vulnerability is classified as an improper state validation issue affecting the Performance API component. No authentication is required; a remote attacker needs only to serve a malicious web page to a user or compromise a website to inject the exploit code. The attack vector is network-based. Google patched this issue in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-78955 disclosed alongside Chrome 152.0.7977.65 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows, Mac, and Linux