Junglewise Threat Intelligence

CVE-2026-11251: Google Chrome insufficient policy enforcement in Password Manager

CVE-2026-11251 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's Password Manager could allow a malicious website to bypass certain security controls. If an attacker has already partially compromised the browser's content rendering process, they could use a specially crafted webpage to gain unauthorized access to password management functions. This could potentially lead to the exposure of saved credentials or unauthorized modification of password settings.

Technical details

This vulnerability is classified as insufficient policy enforcement (CWE-20) within the Password Manager component of Google Chrome. The flaw exists because the browser does not adequately validate or enforce access control policies when a renderer process has been compromised. An attacker who has already achieved code execution within the sandboxed renderer process can leverage a crafted HTML page to bypass discretionary access controls (DAC). This allows the attacker to interact with Password Manager logic that should otherwise be restricted. The issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE-2026-11251 published.

References

Related threats