Executive brief
A vulnerability in Google Chrome's password management component could allow a malicious website to access data from other websites. To succeed, an attacker must trick a user into performing specific interactions or gestures on a specially crafted webpage. This could lead to the unauthorized disclosure of sensitive information across different web domains.
Technical details
An inappropriate implementation vulnerability exists in the Passwords component of Google Chrome prior to version 151.0.7922.72. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by inducing a user to perform specific UI gestures on a malicious HTML page. Successful exploitation results in the leakage of cross-origin data to the attacker's site. This issue is tracked as Chromium security severity Medium and was addressed in the Stable channel update for desktop.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google Chrome Stable channel update published
- 2026-07-30: disclosed: NVD publication date