Executive brief
A security vulnerability in Google Chrome on Android could allow a malicious website to bypass security boundaries designed to keep data from different sites separate. If an attacker has already partially compromised the browser's processing engine, they could use a specially crafted webpage to access sensitive information, such as saved passwords. Users should update their Chrome browser to version 149.0.7827.115 or later to protect their data.
Technical details
This vulnerability is classified as an inappropriate implementation within the Passwords component of Google Chrome for Android. The flaw allows a remote attacker who has already compromised the renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break the security boundary that normally prevents one site from accessing data belonging to another. This could lead to the unauthorized disclosure of sensitive user information, including stored credentials. The issue is resolved in Google Chrome version 149.0.7827.115.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-30: disclosed: Reported to Chromium by Google researchers
- 2026-06-11: patched: Stable channel update released
- 2026-06-11: advisory: NVD publication date