Junglewise Threat Intelligence

CVE-2026-11271: Google Chrome cross-origin data leak in Passwords

CVE-2026-11271 · Severity: info · CVSS 3.3 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's password management component could allow a malicious website to trick a user into leaking sensitive data. By convincing a user to perform specific mouse or keyboard actions on a specially crafted webpage, an attacker could bypass security boundaries to access information from other websites. This could lead to the unauthorized exposure of user data or credentials stored within the browser.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists in the Passwords component of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass cross-origin resource sharing (CORS) or similar security boundaries to leak data from a different origin. Exploitation requires the attacker to host a malicious HTML page and successfully trick a user into performing specific UI gestures (such as clicking or dragging). This interaction triggers the flaw in how the password manager handles data across different web origins. Google has addressed this issue in the stable channel update for desktop.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-05: disclosed: CVE published to NVD

References

Related threats