Executive brief
Google Chrome on Mac contains an authorization flaw in its GPU (graphics processing) component. An attacker who has already compromised a webpage's rendering process could exploit this to access sensitive data from other websites, potentially exposing user information that should be isolated between different origins.
Technical details
This vulnerability is an incorrect authorization flaw in the GPU component of Google Chrome on macOS. The attack requires an attacker to have already compromised the renderer process, which is a sandboxed component responsible for executing website code. The attacker can then craft a malicious HTML page to exploit the authorization weakness and read cross-origin data that should be protected by browser security boundaries. The vulnerability was patched in Chrome version 153.0.8010.36 and later; users on macOS prior to this version are affected.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released