Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media handling component could allow a malicious website to access data from other websites that the user is currently visiting. This type of 'cross-origin' leak can lead to the exposure of sensitive information, such as login tokens or personal data, if a user visits a specially crafted webpage.
Technical details
An inappropriate implementation in the Media component of Google Chrome prior to version 148.0.7778.96 allowed for cross-origin data leakage. The vulnerability is classified as an origin validation error (CWE-346). A remote attacker could exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass Same-Origin Policy (SOP) restrictions to read data from other origins, though it does not provide full system compromise or data modification capabilities. The issue was addressed in the Chrome 148 stable channel update.
Affected products
- Google Chrome prior to 148.0.7778.96
Timeline
- 2026-05-05: patched: Chrome 148.0.7778.96 released to stable channel.
- 2026-05-06: disclosed: CVE published.