Executive brief
A security flaw in Google Chrome's password management component could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into visiting a specially crafted webpage. This could lead to the unauthorized disclosure of sensitive information across different web domains.
Technical details
A vulnerability classified as 'Inappropriate Implementation' or 'Insufficient Data Validation' exists in the Passwords component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries. By convincing a user to visit a maliciously crafted HTML page, the attacker can trigger the vulnerability to leak data from different origins. This is tracked as CWE-863 (Incorrect Authorization). The issue is resolved in Google Chrome version 149.0.7827.155 and later.
Affected products
- Google Chrome < 149.0.7827.155
Timeline
- 2026-05-14: disclosed: Reported to Chromium project
- 2026-06-16: patched: Stable channel update released
- 2026-06-17: advisory: NVD published CVE record