Executive brief
A vulnerability in Google Chrome's password management component could allow a remote attacker to access sensitive information across different websites. This issue requires the attacker to have already partially compromised the browser's rendering process, typically through a separate exploit. If successful, the attacker could leak data that should be protected by the browser's security boundaries, potentially compromising user privacy or account security.
Technical details
This vulnerability is classified as an inappropriate implementation within the Passwords component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin data protections. A precondition for this exploit is that the attacker must have already achieved code execution within a compromised renderer process. By utilizing a specially crafted HTML page, the attacker can then leak data across origins that should otherwise be isolated. The issue was addressed in Google Chrome version 151.0.7922.72. Google has assigned this a 'Low' severity rating within the Chromium security framework.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date