Executive brief
Google Chrome on Windows contains a flaw in its ReadingList feature that fails to properly validate user input. An attacker who has already compromised Chrome's rendering engine can exploit this to bypass web origin policies, potentially allowing unauthorized access to data from different websites.
Technical details
The vulnerability is an improper input validation flaw in ReadingList affecting Google Chrome on Windows prior to version 152.0.7977.65. The attack requires the renderer process to be compromised; the attacker can then use a crafted HTML page to bypass web origin policy restrictions. This is a post-compromise attack vector (renderer process exploitation). The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome Windows prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Published in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows