Executive brief
A vulnerability in the password management component of Google Chrome for Android could allow a malicious website to access sensitive information. By tricking a user into visiting a specially crafted webpage, an attacker could potentially read data from the browser's memory. This could lead to the exposure of private user data or credentials handled by the browser.
Technical details
An information disclosure vulnerability exists in the Passwords component of Google Chrome for Android prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that fails to properly isolate or protect sensitive data within the browser's process memory. A remote attacker can exploit this by hosting a malicious HTML page; when a user visits the page, the attacker can leverage the flaw to read sensitive information from the process memory. This is classified by Chromium as a Medium severity issue and has been addressed in the version 150.0.7871.47 update.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched