Executive brief
A security vulnerability in Google Chrome's password management component could allow an attacker to bypass critical security boundaries. If an attacker has already partially compromised the browser's rendering engine, they could use this flaw to access data from other websites that should normally be isolated. This could lead to the unauthorized access of sensitive user information across different web sessions.
Technical details
This vulnerability is classified as an 'Inappropriate implementation' within the Passwords component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break the security boundary that normally prevents one website from accessing data from another. This issue was resolved in Google Chrome version 149.0.7827.197. The vulnerability was discovered internally by Google.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-13: disclosed: Reported by Google internally
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: advisory: CVE published to NVD