Executive brief
Google Chrome's password manager on Android contains a vulnerability that allows attackers to steal sensitive stored passwords through a malicious web page. An attacker can craft a specially designed HTML page that, when visited by a user, leaks password information without requiring additional user interaction or authentication. This puts millions of Android users' stored credentials at risk of unauthorized access.
Technical details
This is an information disclosure vulnerability in the password storage functionality of Chrome on Android. The vulnerability can be triggered via a crafted HTML page sent over the network, requiring only that a user visit a malicious website. The root cause involves improper access controls or unintended exposure of password data. An attacker can extract sensitive credential information by exploiting this flaw. The vulnerability affects Chrome versions prior to 153.0.8010.36 on Android and has been patched in that release and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36