Executive brief
Google Chrome, a widely used web browser, contained a security flaw in its password management component. If an attacker first compromises the part of the browser that displays web pages, they could then bypass security boundaries to access sensitive data from other websites. This could lead to the unauthorized exposure of user information or credentials across different web services.
Technical details
A vulnerability exists in Google Chrome's Passwords component due to insufficient policy enforcement. The flaw allows a remote attacker who has successfully compromised the renderer process to bypass Same-Origin Policy (SOP) protections. By utilizing a specially crafted HTML page, the attacker can leak sensitive cross-origin data. This vulnerability is mitigated by the requirement of a prior renderer compromise, but it represents a significant sandbox escape or policy bypass within the browser's security model. The issue is resolved in version 151.0.7922.72.
Affected products
- Google Chrome Prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date