Executive brief
A security vulnerability in Google Chrome's Password Manager could allow a malicious website to bypass security boundaries. If an attacker has already partially compromised the browser's content rendering process, they could use this flaw to access data from other websites that should normally be isolated. This could lead to the unauthorized exposure of sensitive user information across different web sessions.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the Password Manager component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break the security boundaries that normally prevent one website from accessing data belonging to another. This issue was addressed in Chrome version 149.0.7827.53. The vulnerability is considered Medium severity by Chromium developers because it requires a pre-existing compromise of the renderer process as a prerequisite for the bypass.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD