Executive brief
Google Chrome's sign-in feature contains a vulnerability that allows attackers to extract sensitive user information through crafted network traffic. An attacker with network access can intercept or manipulate sign-in communications to steal authentication data or personal information without any user interaction required. This poses a direct risk to user account security and confidentiality of sign-in credentials.
Technical details
This is an information disclosure vulnerability in Chrome's SignIn component that allows remote attackers to obtain sensitive information via crafted network traffic. The vulnerability has a CVSS score of 5.9 (Medium severity) and requires network access but no authentication or user interaction. An attacker can exploit this by sending specially crafted network packets to leak sensitive data from the sign-in process. The vulnerability is fixed in Chrome version 152.0.7977.65 and later, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Patched in Chrome 152.0.7977.65 stable release
- 2026-08-25: advisory