Executive brief
Google Chrome is a widely-used web browser used by millions of people to access websites and web applications. A flaw in Chrome's Performance component could allow an attacker to trick users into visiting a malicious website that reads sensitive data from the browser's memory, potentially exposing passwords, tokens, or other confidential information. This vulnerability affects Chrome versions prior to 152.0.7977.65.
Technical details
The vulnerability is an improper state validation flaw in the Performance API component of Google Chrome. The attack requires a remote attacker to craft a malicious HTML page that exploits the state validation weakness, allowing memory reads within the sandbox environment. The attack vector is network-based and requires user interaction (visiting a malicious website). An attacker can achieve arbitrary memory reads within Chrome's sandbox, potentially leading to information disclosure. This vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Published in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65