Executive brief
A vulnerability in Google Chrome's navigation component could allow a malicious website to leak sensitive information from other websites you have open. By tricking a user into visiting a specially crafted webpage, an attacker can use technical side-channels to observe data that should normally be protected by browser security boundaries. This could lead to the unauthorized exposure of private user data or browsing activity.
Technical details
A side-channel information leakage vulnerability exists in the Navigation component of Google Chrome. The flaw, classified as CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass cross-origin isolation boundaries. By hosting a specially crafted HTML page and enticing a user to visit it, the attacker can leverage navigation-related side channels to infer or extract data from different origins. This issue was addressed in Chrome version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2021-10-06: disclosed: Reported to Chromium project by Google researchers
- 2026-05-12: patched: Stable channel update released for Desktop
- 2026-05-14: advisory: NVD publication date