Executive brief
Google Chrome contains a vulnerability in its Scroll component that allows an attacker with control over the renderer process to leak data across website boundaries using a specially crafted webpage. This could enable theft of sensitive information such as browsing data, cached credentials, or personal information from other websites a user is visiting.
Technical details
This is a cross-origin information leak vulnerability in Chrome's Scroll component affecting versions prior to 153.0.8010.36. The vulnerability requires an attacker to have already compromised the renderer process—typically through a separate vulnerability or exploit chain. Given the renderer process compromise requirement, the attack vector is local to the compromised process; however, the initial renderer compromise would likely be achieved via a malicious or compromised website (network vector). An attacker can leverage a crafted HTML page to exfiltrate data from other origins (cross-origin data leak). Google patched this in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36