Executive brief
Google Chrome contains an information disclosure vulnerability in its Editing component that allows remote attackers to access sensitive information by tricking users into visiting a malicious web page. This could expose confidential data, browsing history, or cached content to unauthorized parties without requiring any special user permissions beyond visiting a compromised website.
Technical details
This is an information leak vulnerability in Google Chrome's Editing component, reachable via a crafted HTML page delivered over the network. The vulnerability allows a remote attacker to obtain sensitive information without prior authentication. The flaw was present in Chrome versions prior to 153.0.8010.36 and has been patched in that release. The attack vector requires only that a user visit a malicious website, making this a high-impact but relatively easy-to-exploit issue.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released