Junglewise Threat Intelligence

CVE-2026-14019: Google Chrome cross-origin data leak in Passwords

CVE-2026-14019 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's password management component contained a security flaw that could allow a malicious website to access data from other websites. This type of vulnerability, known as a cross-origin data leak, could potentially expose sensitive user information if a victim visits a specially crafted webpage. Users are advised to update their browser to the latest version to mitigate this risk.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the Passwords component of Google Chrome prior to version 150.0.7871.47. A remote attacker could exploit this by enticing a user to visit a specially crafted HTML page, leading to the leakage of cross-origin data. This bypasses the Same-Origin Policy (SOP) which is designed to prevent websites from accessing data belonging to other domains. The vulnerability was assigned a Medium severity rating by the Chromium security team. The issue is addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Google Chrome release announcement published.
  • 2026-06-30: patched: Fixed in version 150.0.7871.47.

References

Related threats