Description
Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is due to an insecure implementation in Chrome's password handling component, exposing a heap corruption vulnerability that can be triggered by a crafted web page. An attacker could send a malicious HTML document to a user’s browser, causing a remote participant’s memory to be corrupted and potentially leading to a crash, denial of service, or alteration of execution flow. This issue is classified as CWE-20, indicating improper input validation of user‑supplied data.

Affected Systems

All releases of Google Chrome older than version 150.0.7871.47 are affected. The vulnerability resides in the password management subsystem. The advisory does not provide explicit platform coverage; therefore, we cannot confirm which specific operating systems are impacted, but the impact could extend to any platform where Chrome is installed.

Risk and Exploitability

The CVSS score of 8.8 reflects the high potential impact if exploited. The EPSS score is less than 1%, indicating a very low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker convincing a user to visit a malicious page, which then triggers the heap corruption. Consequently, while the exploitation risk remains moderate due to the low EPSS, the severity warrants timely remediation.

Generated by OpenCVE AI on July 21, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later
  • Enable automatic updates so future patches are applied without manual action
  • Monitor Google Chrome release announcements and Chromium issue tracker for new advisories

Generated by OpenCVE AI on July 21, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Remote Heap Corruption via Malicious Password HTML in Chrome

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Remote Heap Corruption via Malicious Password HTML in Chrome

Mon, 13 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption Vulnerability in Chrome Password Manager

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Heap Corruption Vulnerability in Chrome Password Manager

Thu, 09 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Chrome Password Handling Heap Corruption via Crafted HTML

Wed, 08 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome Password Handling Heap Corruption via Crafted HTML

Wed, 08 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Inadequate Password Handling Enables Remote Heap Corruption in Chrome

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Inadequate Password Handling Enables Remote Heap Corruption in Chrome

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Malicious Password Handling in Chrome

Sun, 05 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Malicious Password Handling in Chrome

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted Password Page in Google Chrome

Sat, 04 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted Password Page in Google Chrome

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote Heap Corruption via Crafted HTML Page in Chrome Password Feature

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Heap Corruption via Crafted HTML Page in Chrome Password Feature

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption in Chrome Password Handling via Malicious HTML

Fri, 03 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption in Chrome Password Handling via Malicious HTML

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Password Feature Vulnerability Enables Remote Heap Corruption

Thu, 02 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Chrome Password Feature Vulnerability Enables Remote Heap Corruption

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted HTML Page in Chrome Password Handling
Weaknesses CWE-119
CWE-787

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted HTML Page in Chrome Password Handling
Weaknesses CWE-119
CWE-787

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted HTML in Chrome Passwords
Weaknesses CWE-119
CWE-787

Wed, 01 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted HTML in Chrome Passwords
Weaknesses CWE-119
CWE-787

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:27:56.851Z

Reserved: 2026-06-29T23:04:17.173Z

Link: CVE-2026-14009

cve-icon Vulnrichment

Updated: 2026-07-01T14:25:15.653Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T16:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation