Executive brief
Google Chrome's FoldableAPIs contain an information leak vulnerability that allows attackers to extract sensitive data through a malicious HTML page. This could expose user information or internal system details to remote attackers without requiring any user authentication or interaction beyond visiting a crafted webpage.
Technical details
An information leak vulnerability exists in Google Chrome's FoldableAPIs component prior to version 152.0.7977.65. The vulnerability allows a remote attacker to obtain sensitive information by crafting a malicious HTML page. The attack requires user interaction (visiting the malicious page) but does not require authentication. The vulnerability is in the FoldableAPIs implementation, which handles foldable device screen geometry and state. An attacker can craft HTML that exploits this API to leak sensitive data about device state or internal browser information. The vulnerability was patched in Chrome 152.0.7977.65, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: patched: Chrome 152.0.7977.65 released with fix
- 2026-08-25: disclosed