Junglewise Threat Intelligence

CVE-2026-6312: Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the rend

CVE-2026-6312 · Severity: low · CVSS 3.1 · Published 2026-04-15

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser for accessing internet services and internal applications. A security flaw in the browser's password management component could allow a malicious website to steal sensitive data from other websites. This could lead to the exposure of user credentials or personal information if a user visits a specially crafted page while their browser is already partially compromised.

Technical details

An improper access control vulnerability (CWE-284) exists in the Password management component of Google Chrome. The flaw stems from insufficient policy enforcement, which can be exploited by a remote attacker who has already achieved code execution within a compromised renderer process. By enticing a user to visit a malicious HTML page, the attacker can bypass cross-origin restrictions to leak sensitive data. This vulnerability is mitigated by the requirement of a prior renderer compromise and user interaction. Google has addressed this issue in version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-31: other: Reported to Google
  • 2026-04-15: disclosed: Vulnerability details published by NVD
  • 2026-04-15: patched: Fixed in Chrome version 147.0.7727.101/102

References

Related threats