Executive brief
Google Chrome's WebMCP component contains an information leak vulnerability that could allow attackers to access cross-origin data if the browser's rendering engine has already been compromised. This affects users of Chrome versions before 153.0.8010.36, though the attack requires a pre-existing compromise of the renderer process. The issue is fixed in Chrome 153.0.8010.36 and later.
Technical details
This is an information disclosure vulnerability in WebMCP (Web Message Channel Protocol), a component handling cross-origin messaging in Chrome's renderer process. The vulnerability allows a remote attacker with an already-compromised renderer process to extract cross-origin data via a specially crafted HTML page, breaking the same-origin policy. Attack precondition: the renderer process must already be compromised through another vulnerability. The vulnerability affects Chrome versions prior to 153.0.8010.36, which includes the fix (reported in Chrome 153 stable release on 2026-09-08).
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36