Executive brief
Google Chrome is a widely-used web browser that millions of users rely on to access websites and web applications safely. This vulnerability allows a remote attacker to obtain sensitive information by tricking a user into visiting a specially crafted webpage. No user interaction beyond visiting the page is required, and the vulnerability could expose private data such as browsing history or cached information.
Technical details
The vulnerability is a missing authorization flaw in the Actor component of Google Chrome. An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when loaded in the browser, bypasses intended access controls and retrieves sensitive information. The attack requires only that a user visit the crafted webpage and does not require any special browser configuration. The flaw was fixed in Chrome version 153.0.8010.36 and later releases.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched