Executive brief
A security vulnerability in Google Chrome on Android could allow a remote attacker to access sensitive data from other websites. This occurs when an attacker uses a specially crafted webpage to bypass security boundaries that normally keep data from different sites separate. To exploit this, an attacker would first need to have already compromised a specific part of the browser's internal processing system.
Technical details
An insufficient policy enforcement vulnerability exists in the Network component of Google Chrome for Android. The flaw allows a remote attacker who has already compromised the renderer process to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a crafted HTML page, the attacker can leak cross-origin data. This vulnerability is addressed in version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Stable channel update released for desktop and Android versions.
- 2026-05-14: disclosed: CVE published to the NVD.