Junglewise Threat Intelligence

CVE-2026-12032: Google Chrome for Android site isolation bypass in Passwords

CVE-2026-12032 · Severity: info · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome on Android could allow a malicious website to bypass security boundaries designed to keep data from different sites separate. If an attacker has already partially compromised the browser's processing engine, they could use a specially crafted webpage to access sensitive information, such as saved passwords. Users should update their Chrome browser to version 149.0.7827.115 or later to protect their data.

Technical details

This vulnerability is classified as an inappropriate implementation within the Passwords component of Google Chrome for Android. The flaw allows a remote attacker who has already compromised the renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break the security boundary that normally prevents one site from accessing data belonging to another. This could lead to the unauthorized disclosure of sensitive user information, including stored credentials. The issue is resolved in Google Chrome version 149.0.7827.115.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-30: disclosed: Reported to Chromium by Google researchers
  • 2026-06-11: patched: Stable channel update released
  • 2026-06-11: advisory: NVD publication date

References

Related threats