Description
Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient enforcement of the password policy in Chrome before 150.0.7871.47 allows a remote attacker who already compromised a renderer process to load a specially crafted HTML page that reads data from other origins, resulting in cross‑origin information disclosure. The flaw stems from improper access control (CWE‑284) in the password handling code.

Affected Systems

All Chrome installations prior to version 150.0.7871.47 on any operating system or release channel are vulnerable. Exploitation requires a renderer process to be compromised first, which can occur through other bugs, malicious extensions, or social engineering.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. With an EPSS score of less than 1 % the likelihood of exploitation is low, and it is not listed in the CISA KEV catalog. Exploitation necessitates that the attacker first gain a foothold in a renderer process; once achieved, a malicious HTML page can extract cross‑origin data via improper access control.

Generated by OpenCVE AI on August 3, 2026 at 06:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer
  • Enable Site Isolation so that renderer processes run in separate, secure contexts
  • Restrict or disable third‑party extensions that could provide a renderer foothold

Generated by OpenCVE AI on August 3, 2026 at 06:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Chromium Password Policy Bypass Enabling Cross‑Origin Data Leak

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Cross‑origin data leakage via compromised renderer in Chrome

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Cross‑origin data leakage via compromised renderer in Chrome

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Password Policy Enforcement Failure in Google Chrome

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Password Policy Enforcement Failure in Google Chrome

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Compromise Enables Cross‑Origin Data Leakage via Password Policy Bypass

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Compromise Enables Cross‑Origin Data Leakage via Password Policy Bypass

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Compromised Renderer due to Weak Password Policy in Chrome

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Compromised Renderer due to Weak Password Policy in Chrome

Tue, 07 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Password Policy Bypass in Chrome

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Password Policy Bypass in Chrome

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Password Policy Bypass in Google Chrome

Sun, 05 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Cross‑origin Data Leakage via Password Policy Bypass in Google Chrome

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Password Policy Enforcement Failure Allows Cross‑Origin Data Leakage When Renderer Compromised

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Password Policy Enforcement Failure Allows Cross‑Origin Data Leakage When Renderer Compromised

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Passwords Module in Google Chrome
Weaknesses CWE-200
CWE-285

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Passwords Module in Google Chrome
Weaknesses CWE-200
CWE-285

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Insecure Policy Enforcement in Chrome
Weaknesses CWE-200
CWE-285

Wed, 01 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Insecure Policy Enforcement in Chrome
Weaknesses CWE-200
CWE-285

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T13:50:38.879Z

Reserved: 2026-06-29T23:03:56.589Z

Link: CVE-2026-13937

cve-icon Vulnrichment

Updated: 2026-07-02T13:48:05.623Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:45:04Z

Weaknesses