Executive brief
Google Chrome contains a flaw in its navigation handling that can leak data across different websites. An attacker can craft a malicious webpage that, when visited by a user, exploits this navigation discrepancy to steal sensitive information from other sites the user may have open. This could expose personal or corporate data without the user's knowledge.
Technical details
This vulnerability is an observable discrepancy in Chrome's navigation implementation that enables cross-origin data leakage. An attacker can craft a malicious HTML page that exploits navigation timing or state differences to infer or extract sensitive data from cross-origin resources. The attack requires user interaction (visiting a malicious page) but does not require authentication. The vulnerability affects Chrome versions prior to 153.0.8010.36 and was patched in that release.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released