Executive brief
Google Chrome's Frame handling mechanism contains an information leak vulnerability that allows attackers to extract sensitive data through a malicious HTML page. An attacker could craft a webpage that, when visited by a Chrome user, leaks confidential information such as authentication tokens, cached data, or other sensitive content from the browser's memory.
Technical details
This vulnerability is a information disclosure flaw in Chrome's Frame rendering component that occurs prior to version 153.0.8010.36. The vulnerability is triggered when a remote attacker delivers a specially crafted HTML page to a user. No authentication or special preconditions are required—the attack succeeds through normal web browsing. An attacker can exploit this to leak sensitive information from the browser's memory or other protected data. The fix is available in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released