Executive brief
A vulnerability in the Google Chrome Password Manager could allow a malicious website to bypass security controls. If a user visits a specially crafted webpage, an attacker might be able to access or interact with stored password data in ways that should normally be restricted. This could lead to the unauthorized disclosure of sensitive login credentials.
Technical details
A policy enforcement vulnerability exists in the Password Manager component of Google Chrome. The flaw is rooted in insufficient discretionary access control (DAC) checks when processing web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page, which leverages the lack of enforcement to bypass security boundaries. This could potentially allow the attacker to access or manipulate password-related data. The issue is resolved in Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.