Executive brief
Google Chrome's password management component contained a security flaw that could allow a malicious website to access data from other websites. This type of vulnerability, known as a cross-origin data leak, could potentially expose sensitive user information if a victim visits a specially crafted webpage. Users are advised to update their browser to the latest version to mitigate this risk.
Technical details
A vulnerability classified as an 'inappropriate implementation' exists in the Passwords component of Google Chrome prior to version 150.0.7871.47. A remote attacker could exploit this by enticing a user to visit a specially crafted HTML page, leading to the leakage of cross-origin data. This bypasses the Same-Origin Policy (SOP) which is designed to prevent websites from accessing data belonging to other domains. The vulnerability was assigned a Medium severity rating by the Chromium security team. The issue is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Google Chrome release announcement published.
- 2026-06-30: patched: Fixed in version 150.0.7871.47.