Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's data transfer component could allow a malicious website to access sensitive information from the computer's memory. To succeed, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage.
Technical details
An improper input validation vulnerability (CWE-20) exists in the DataTransfer component of Google Chrome. A remote attacker can exploit this by hosting a malicious HTML page and convincing a user to perform specific UI gestures (such as drag-and-drop or clipboard actions). Successful exploitation allows the attacker to read sensitive information from the browser's process memory. While the reported CVSS score is 5.3 (Medium), Chromium has assigned this a 'Critical' security severity. The issue is resolved in version 148.0.7778.168 and later.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-03-26: other: Reported by Google internal researchers
- 2026-05-12: patched: Fixed in version 148.0.7778.168
- 2026-05-14: disclosed: Public advisory published