Executive brief
A vulnerability in Google Chrome's password management component could allow a malicious website to access data from other websites. If a user visits a specially crafted webpage, an attacker could potentially leak sensitive cross-origin information. This poses a risk to user privacy and the confidentiality of data handled by the browser.
Technical details
An inappropriate implementation vulnerability exists within the Passwords component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation boundaries and leak sensitive data. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Chromium developers have assigned this a Medium severity rating.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed