Junglewise Threat Intelligence

CVE-2026-12458: Google Chrome UI misrepresentation in Passwords

CVE-2026-12458 · Severity: low · CVSS 3.1 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's password management interface could allow a malicious website to trick users into revealing sensitive information. By convincing a user to perform specific interactions on a specially crafted webpage, an attacker could potentially leak data across different websites. This could lead to the exposure of private user information or credentials stored within the browser.

Technical details

A vulnerability classified as User Interface (UI) Misrepresentation (CWE-451) exists in the Passwords component of Google Chrome. The flaw stems from an inappropriate implementation of security UI, which allows a remote attacker to bypass cross-origin protections. To exploit this, an attacker must host a crafted HTML page and convince a user to perform specific UI gestures. Successful exploitation enables the leakage of cross-origin data. The issue is resolved in Google Chrome version 149.0.7827.155 and later.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-27: disclosed: Reported to Chromium by Google researchers.
  • 2026-06-16: patched: Stable channel update released.
  • 2026-06-17: advisory: NVD advisory published.

References

Related threats