Executive brief
A vulnerability in Google Chrome's ViewTransitions feature allowed remote attackers to access data from other websites. By tricking a user into visiting a specially crafted webpage, an attacker could bypass security boundaries to leak sensitive information. This could lead to the exposure of private user data or session information from different origins.
Technical details
An insufficient policy enforcement vulnerability exists in the ViewTransitions component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit this, an attacker must entice a user to visit a malicious website containing a crafted HTML page. Successful exploitation results in the unauthorized disclosure of information from other web origins. The issue is resolved in Chrome version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-03-24: other: Reported to Chromium by Google researchers
- 2026-05-12: patched: Stable channel update released for desktop
- 2026-05-14: disclosed: CVE published to NVD