Executive brief
A security issue was identified in the password management component of Google Chrome for macOS. A local attacker with access to the machine could potentially extract sensitive information, such as stored credentials, from the browser's memory by using a specially crafted file. This could lead to the unauthorized disclosure of user account information and other private data.
Technical details
An information disclosure vulnerability exists in the Passwords component of Google Chrome for macOS due to an inappropriate implementation. The flaw allows a local attacker to read potentially sensitive information from the browser's process memory. Exploitation requires the attacker to provide a malicious file to the system. The vulnerability is addressed in Google Chrome version 150.0.7871.47 for Mac. The Chromium project classified this as a Medium severity issue.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched