Executive brief
A vulnerability in Google Chrome's password management interface could allow a malicious website to trick users into revealing sensitive information. By convincing a user to perform specific interactions on a specially crafted webpage, an attacker could potentially leak data across different websites. This could lead to the exposure of private user information or credentials stored within the browser.
Technical details
A vulnerability classified as User Interface (UI) Misrepresentation (CWE-451) exists in the Passwords component of Google Chrome. The flaw stems from an inappropriate implementation of security UI, which allows a remote attacker to bypass cross-origin protections. To exploit this, an attacker must host a crafted HTML page and convince a user to perform specific UI gestures. Successful exploitation enables the leakage of cross-origin data. The issue is resolved in Google Chrome version 149.0.7827.155 and later.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-27: disclosed: Reported to Chromium by Google researchers.
- 2026-06-16: patched: Stable channel update released.
- 2026-06-17: advisory: NVD advisory published.