Executive brief
Google Chrome is a widely-used web browser that processes web pages containing styling and layout information (CSS). A flaw in how Chrome handles CSS allowed attackers to craft malicious web pages that could extract sensitive information from the browser, such as user data or site content that should have been hidden. An attacker could exploit this by tricking users into visiting a specially designed webpage.
Technical details
This vulnerability is an information leak in the CSS (Cascading Style Sheets) processing component of Google Chrome versions prior to 152.0.7977.65. The flaw allows a remote attacker to obtain sensitive information through a crafted HTML page, likely by exploiting improper access controls or state isolation in CSS rendering. The attack vector is network-based and requires user interaction (visiting a malicious webpage). Chrome 152 and later versions contain the fix. No evidence of active exploitation in the wild has been reported.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65