Junglewise Threat Intelligence

CVE-2026-12446: Google Chrome cross-origin data leak in Passwords

CVE-2026-12446 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security flaw in Google Chrome's password management component could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into visiting a specially crafted webpage. This could lead to the unauthorized disclosure of sensitive information across different web domains.

Technical details

A vulnerability classified as 'Inappropriate Implementation' or 'Insufficient Data Validation' exists in the Passwords component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries. By convincing a user to visit a maliciously crafted HTML page, the attacker can trigger the vulnerability to leak data from different origins. This is tracked as CWE-863 (Incorrect Authorization). The issue is resolved in Google Chrome version 149.0.7827.155 and later.

Affected products

  • Google Chrome < 149.0.7827.155

Timeline

  • 2026-05-14: disclosed: Reported to Chromium project
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD published CVE record

References

Related threats