Executive brief
A security issue in Google Chrome's password management component could allow a malicious website to access data from other websites. This occurs if an attacker has already partially compromised the browser's internal processing systems. Such an exploit could lead to the unauthorized disclosure of sensitive user information across different web domains.
Technical details
A vulnerability exists in Google Chrome's Passwords component due to insufficient policy enforcement. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this flaw by enticing a user to visit a specially crafted HTML page. This allows the attacker to bypass cross-origin restrictions and leak sensitive data from other origins. The issue is resolved in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched