MEDIUM
CVE-2026-13022
CVSS
6.5
Description
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
A flaw in Google Chrome's Autofill implementation prior to version 149.0.7827.197 allowed a compromised renderer process to leak cross-origin data through a crafted HTML page. This is an implementation bug where Autofill incorrectly handled cross-origin boundaries, enabling data exfiltration when combined with renderer compromise.
Mitigation
Update Google Chrome to version 149.0.7827.197 or later. In enterprise environments, deploy the update via centralized endpoint management and verify adoption across managed devices.
Weakness (CWE)
CWE-346
EPSS Score
0.2%
Probability of exploitation in next 30 days
9.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.