Executive brief
A security vulnerability in Google Chrome's password management component on Windows could allow an attacker to gain elevated privileges on a user's system. To exploit this, an attacker would first need to compromise the browser's content-rendering process and then trick a user into visiting a specially crafted webpage. This could lead to unauthorized access to sensitive information or the ability to perform actions with higher-level system permissions.
Technical details
An insufficient policy enforcement vulnerability exists in the Passwords component of Google Chrome on Windows. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to bypass security boundaries and escalate privileges. This is achieved by enticing a user to load a specially crafted HTML page. The vulnerability is addressed in Chrome version 148.0.7778.168 for Windows.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-30: disclosed: Reported to Chrome by Google internal researchers
- 2026-05-12: patched: Stable channel update released for Windows
- 2026-05-14: advisory: NVD publication date