Junglewise Threat Intelligence

CVE-2026-13933: Google Chrome insufficient policy enforcement in Passwords

CVE-2026-13933 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's password management component could allow an attacker to access sensitive information. If a user visits a malicious website and the attacker has already partially compromised the browser's internal processing, they could read data from the browser's memory. This could lead to the exposure of private user information or credentials.

Technical details

An insufficient policy enforcement vulnerability exists in the Passwords component of Google Chrome prior to version 150.0.7871.47. The flaw allows a remote attacker who has already compromised the renderer process to bypass security boundaries and read sensitive information from process memory. Exploitation requires the victim to navigate to a specially crafted HTML page. This vulnerability is categorized by Chromium as Medium severity and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats