Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
The vulnerability consists of information leakage through a side-channel in the V8 engine. An attacker is able to read data belonging to other origins (cross-origin), which constitutes a violation of the same-origin policy. The mechanism is based on observing differences in timing or resource behavior of the JavaScript engine (CWE-203: Observable Discrepancy), which allows inferring the contents of data that is not directly accessible. It is sufficient for the victim to visit a malicious HTML page prepared by the attacker.
An attacker may gain access to sensitive data belonging to other websites (cross-origin), such as session tokens, credentials, or other sensitive information processed by the browser. Data integrity is not directly threatened, however the confidentiality breach may lead to further attacks.
Google Chrome should be updated to version 140.0.7339.207 or newer. The update is available through the browser's built-in update mechanism or directly from the vendor's website (chromereleases.googleblog.com).
Google Chrome in versions earlier than 140.0.7339.207 on Microsoft Windows, Linux, and Apple macOS systems.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApple macOS
OSAppleall versionsGoogle Chrome
APPGoogle< 140.0.7339.207Linux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP