Executive brief
A vulnerability in Google Chrome's Password Manager could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different web domains. Google has released an update to address this issue in Chrome version 149.0.7827.53.
Technical details
An inappropriate implementation vulnerability exists in the Password Manager component of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit this, an attacker must entice a user to visit a specifically crafted HTML page. Successful exploitation could result in the disclosure of sensitive information from origins other than the attacker's site. The issue is addressed in the stable channel update for desktop (Windows, Mac, and Linux).
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published to NVD.