Executive brief
Google Chrome is a widely-used web browser. An information leak vulnerability in Chrome's DataTransfer functionality could allow an attacker to extract sensitive information (such as clipboard data or drag-and-drop content) by tricking a user into visiting a malicious webpage. This could expose confidential data like passwords, personal information, or corporate documents.
Technical details
This vulnerability is an information leak in the DataTransfer component of Google Chrome prior to version 152.0.7977.65. The vulnerability is triggered via a crafted HTML page, suggesting the attack vector is network-based and requires user interaction (visiting a malicious page). An attacker can exploit this to obtain sensitive information exposed through the DataTransfer API. The issue has been patched in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched