Cross-Origin Data Leak in Google Chrome
CVE-2026-5283

6.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-5283?

A vulnerability in the ANGLE component of Google Chrome prior to a specific version can be exploited by remote attackers to extract sensitive cross-origin data. This occurs through the use of a maliciously crafted HTML page, which enables data leakage across different domains. Users are encouraged to update their browsers promptly to safeguard against potential exploitation.

Affected Version(s)

Chrome 146.0.7680.178

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.