Executive brief
Google Chrome's prefetch mechanism contains a flaw that allows attackers to leak sensitive data across website boundaries through a specially crafted web page. When a user visits a malicious page, an attacker can infer information about the user's activity on other websites, compromising privacy.
Technical details
This vulnerability is an information disclosure flaw in Chrome's prefetch functionality that creates an observable discrepancy allowing cross-origin data leakage. An attacker crafting a malicious HTML page can trigger prefetch requests and detect timing or state differences to infer whether a user has accessed specific cross-origin resources. The attack is network-based and requires only that a user visit the attacker's webpage; no authentication or special user interaction is needed beyond normal browsing. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026, and is classified as Low severity by Chromium's internal assessment.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched