Executive brief
Google Chrome's credential provider component on Windows contains a logic flaw that could allow an attacker who has compromised the browser's rendering engine to leak sensitive user credentials or authentication data. An attacker would need to trick the user into visiting a malicious webpage after the renderer process has already been compromised, but successful exploitation could result in unauthorized access to user accounts and sensitive information.
Technical details
This vulnerability is a confused deputy issue in Chrome's CredentialProvider component on Windows, where the credential provider fails to properly validate requests from the renderer process. The vulnerability requires an attacker to have already compromised the renderer process and then deliver a crafted HTML page to trigger information disclosure. The attack vector is network-based but requires a precondition of prior renderer process compromise. Patches are available in Chrome version 152.0.7977.75 and later. The Chromium security team classified this as a low-severity issue despite the medium CVSS score.
Affected products
- Google Chrome prior to 152.0.7977.75 on Windows
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in Chrome 152.0.7977.75