Executive brief
A security vulnerability in Google Chrome's password management component could allow a malicious website to bypass standard security boundaries. By tricking a user into visiting a specially crafted webpage, an attacker could potentially access data from other websites that should normally be protected. This could lead to the unauthorized disclosure of sensitive information or session data.
Technical details
This vulnerability is classified as a Same Origin Policy (SOP) bypass resulting from insufficient policy enforcement within Google Chrome's password management logic. A remote attacker can exploit this by hosting a malicious HTML page and inducing a user to visit it. Successful exploitation allows the attacker to bypass origin-based security restrictions, potentially leading to cross-origin data access. The issue was addressed in Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.
Affected products
- Google Chrome Prior to 150.0.7871.115
Timeline
- 2026-06-14: disclosed: Reported to Google by internal researchers.
- 2026-07-08: patched: Fixed in Stable Channel Update 150.0.7871.114/.115.
- 2026-07-08: advisory