Junglewise Threat Intelligence

CVE-2026-11032: Google Chrome cross-origin data leak in Password Manager

CVE-2026-11032 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Password Manager could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different web domains. Google has released an update to address this issue and protect user data.

Technical details

A cross-origin data leak vulnerability exists in the Password Manager component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly enforce origin boundaries when handling password-related data. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass Same-Origin Policy (SOP) protections and access sensitive data belonging to other origins. This issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11032 published.

References

Related threats