Executive brief
Google Chrome is a web browser used by millions worldwide to access websites and web applications. A vulnerability in Chrome's network handling allows remote attackers to obtain sensitive information by crafting a malicious HTML page and tricking users into visiting it, potentially exposing user data during web sessions.
Technical details
This vulnerability is an observable discrepancy (information disclosure) in Chrome's network component, allowing a remote attacker to infer or extract sensitive information through timing side-channel or behavioral analysis via a crafted HTML page. The attack requires no special privileges and can be delivered through a network vector (malicious website). The vulnerability affects Chrome versions prior to 152.0.7977.65, and a patch is available in Chrome 152.0.7977.65 and later released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65