Executive brief
A vulnerability in Google Chrome's password management component could allow a malicious website to access sensitive data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private information across different web domains. Google has released an update to address this issue and protect user data.
Technical details
This vulnerability is classified as an inappropriate implementation within the Passwords module of Google Chrome. It allows a remote attacker to bypass cross-origin isolation boundaries and leak data from different origins. The attack is delivered via a crafted HTML page and requires the victim to navigate to the malicious site (User Interaction). Successful exploitation results in the unauthorized disclosure of sensitive information. The issue was addressed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-06-08: patched: Stable channel update released for desktop.
- 2026-06-09: disclosed: NVD publication date.