Impact
Google Chrome’s Password Manager has insufficient input validation for untrusted HTML content. The flaw allows an attacker who already controls the renderer process to deliver a crafted page that can escape the browser sandbox. If the escape succeeds, the attacker may execute code or elevate privileges on the host system. The vulnerability is present in all Chrome builds before 149.0.7827.53.
Affected Systems
The issue affects every Chrome desktop build on the stable channel older than version 149.0.7827.53. The June 2026 update released to the stable channel addresses the flaw, so users of Windows, macOS, or Linux running outdated stable versions are impacted.
Risk and Exploitability
Chromium rates the vulnerability as medium severity. The CVSS score is 7.5, indicating high severity, but the EPSS score is < 1%, showing low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to already compromise the renderer process, narrowing the attack surface. Once that condition is met, a sandbox escape could lead to remote code execution or privilege escalation, representing a moderate to high risk for affected systems.
OpenCVE Enrichment
Debian DSA