Executive brief
Google Chrome is a widely used web browser for accessing internet services and internal applications. A security flaw in the browser's password management component could allow a malicious website to steal sensitive data from other websites. This could lead to the exposure of user credentials or personal information if a user visits a specially crafted page while their browser is already partially compromised.
Technical details
An improper access control vulnerability (CWE-284) exists in the Password management component of Google Chrome. The flaw stems from insufficient policy enforcement, which can be exploited by a remote attacker who has already achieved code execution within a compromised renderer process. By enticing a user to visit a malicious HTML page, the attacker can bypass cross-origin restrictions to leak sensitive data. This vulnerability is mitigated by the requirement of a prior renderer compromise and user interaction. Google has addressed this issue in version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-31: other: Reported to Google
- 2026-04-15: disclosed: Vulnerability details published by NVD
- 2026-04-15: patched: Fixed in Chrome version 147.0.7727.101/102