Executive brief
Google Chrome contains a flaw in the Select element rendering that allows remote attackers to detect discrepancies in how options are displayed. An attacker can craft a malicious HTML page that exploits this to infer sensitive information about user selections or page state without explicit user knowledge or consent.
Technical details
This vulnerability is an observable timing or rendering discrepancy in the Chrome Select element implementation (CWE-203: Observable Discrepancy). An attacker can craft a specially formed HTML page to detect subtle differences in how Chrome renders or processes Select elements, potentially leaking information about user selections or internal state. The attack is network-based and requires only that a user visit a malicious webpage; no authentication or prior access is required. An attacker can obtain sensitive information through repeated observations of the rendering behavior. The vulnerability is patched in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released