Executive brief
Google Chrome is a web browser used by hundreds of millions of people for browsing the internet. This vulnerability allows an attacker to leak sensitive information from a user's browser by crafting a malicious webpage and using social engineering to trick the user into visiting it. While the exposure is limited by requiring user interaction, it could potentially result in data theft or account compromise.
Technical details
This vulnerability is a improper input validation flaw in the Network component of Google Chrome on Windows. An attacker can leverage social engineering to trick users into visiting a crafted HTML page that exploits the vulnerability, potentially leading to the leakage of sensitive information. The vulnerability affects Chrome versions prior to 152.0.7977.65 on Windows. The attack requires user interaction (visiting a malicious page) and no authentication. A fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 released