Executive brief
Google Chrome contains an information leak vulnerability in ControlledFrame that allows a remote attacker with a compromised renderer process to access sensitive information through a crafted HTML page. While this requires an already-compromised renderer, it could enable further exploitation and data theft from users' browsing sessions.
Technical details
This is an information disclosure vulnerability in the ControlledFrame component of Google Chrome versions prior to 153.0.8010.36. The vulnerability allows a remote attacker who has already compromised the Chrome renderer process to exfiltrate sensitive information by crafting a malicious HTML page. The attack requires the renderer to be in a compromised state (e.g., through a prior code execution vulnerability), but does not require additional user interaction beyond normal browsing. Google patched this issue in Chrome 153.0.8010.36 released on September 8, 2026, as part of a security update addressing 230 total security fixes.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36