Junglewise Threat Intelligence

CVE-2026-10937: Google Chrome Same Origin Policy bypass in Passwords

CVE-2026-10937 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's password management component could allow a malicious website to bypass standard security boundaries. By tricking a user into visiting a specially crafted webpage, an attacker could potentially access sensitive information or perform actions on other websites as if they were the user. This undermines the Same-Origin Policy, which is a fundamental security feature designed to keep data from different websites isolated.

Technical details

An inappropriate implementation in the Passwords component of Google Chrome prior to version 149.0.7827.53 allowed a remote attacker to bypass the Same-Origin Policy (SOP). The vulnerability is triggered when a user navigates to a malicious, specially crafted HTML page. Successful exploitation allows the attacker to cross origin boundaries, potentially leading to unauthorized access to sensitive data or session hijacking. Google has addressed this issue in the stable channel update for desktop.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-14: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 update
  • 2026-06-04: advisory: NVD publication date

References

Related threats