Executive brief
Google Chrome's password manager contains a flaw in how it validates user input, which could allow an attacker to leak sensitive password information through specially crafted network traffic. This impacts Chrome users who rely on the browser's built-in password storage feature, potentially exposing stored credentials to attackers who can send malicious network packets to a victim's system.
Technical details
The vulnerability is an improper input validation flaw in Chrome's password handling component, classified as Medium severity by Chromium. An unauthenticated remote attacker can craft malicious network traffic to trigger the vulnerability and potentially leak sensitive information stored in the password manager. The attack does not require user interaction beyond normal browsing. The vulnerability has been fixed in Chrome version 153.0.8010.36 and later; users should update to this version or newer to remediate the issue.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released