Description
Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome’s Password Manager contains an inappropriate implementation that allows a remote attacker to leak cross‑origin data through a crafted HTML page. When a victim visits such a page, the attacker can obtain credentials that the browser would normally autofill from a different domain, resulting in disclosure of sensitive login information.

Affected Systems

The flaw affects the Chrome browser on desktop operating systems. Versions prior to 149.0.7827.53 are known to be vulnerable, though the vulnerability may exist in other earlier releases as well.

Risk and Exploitability

The Chromium team rated this vulnerability as Medium severity. The exploit is remote and can be triggered simply by delivering a malicious web page to the victim with a Chrome installation that has the Password Manager enabled. No local privilege escalation is required and no special network configuration is necessary. EPSS information is unavailable and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on June 5, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest stable release, 149.0.7827.53 or newer.
  • Disable the Password Manager feature permanently via the Chrome policies or the settings at chrome://settings/passwords if the environment requires it.
  • Configure sites to use strict same‑origin policies and avoid auto‑filling passwords on potentially untrusted pages, or use extensions that block autofill on third‑party sites.

Generated by OpenCVE AI on June 5, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Chrome Password Manager
Weaknesses CWE-200

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:04:49.374Z

Reserved: 2026-06-04T17:06:46.199Z

Link: CVE-2026-11083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:17:13.103

Modified: 2026-06-04T23:17:13.103

Link: CVE-2026-11083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T03:30:30Z

Weaknesses