Executive brief
Google Chrome's password management component contained a flaw that could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into performing specific interactions or gestures on a specially crafted webpage. If successful, this could lead to the unauthorized disclosure of sensitive user information across different web domains.
Technical details
A vulnerability classified as an 'inappropriate implementation' exists in the Passwords component of Google Chrome prior to version 151.0.7922.72. The flaw allows a remote attacker to bypass cross-origin isolation boundaries to leak data. Exploitation requires the attacker to host a malicious HTML page and successfully convince a user to perform specific UI gestures, which triggers the data leak. This issue is tracked by Chromium as a High severity security flaw. Google has addressed this vulnerability in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date