Executive brief
A vulnerability in the Google Chrome Password Manager could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information. Users should update their browser to the latest version to prevent this type of cross-site data leakage.
Technical details
An inappropriate implementation vulnerability exists in the Password Manager component of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by enticing a user to visit a specially crafted HTML page. Successful exploitation enables the attacker to leak data across origins, potentially exposing sensitive user information handled by the Password Manager. The vulnerability is triggered via the network vector and requires minimal user interaction (visiting a site). Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published