Google · Google Chrome · CVE-2026-78960
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 152.0.7977.65
**Description**
An information leak exists in the Extensions component. A remote attacker can use social engineering to obtain cross-origin data by utilizing a crafted Chrome extension. Cross-origin data refers to information belonging to a different origin (domain, protocol, or port) than the one requesting it.
**Recommendations**
Update Google Chrome to version 152.0.7977.65 or later.