MEDIUM

CVE-2026-13022

Google Chrome 2026-06-24 CVSS v3.1
CVSS
6.5

Description

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

A flaw in Google Chrome's Autofill implementation prior to version 149.0.7827.197 allowed a compromised renderer process to leak cross-origin data through a crafted HTML page. This is an implementation bug where Autofill incorrectly handled cross-origin boundaries, enabling data exfiltration when combined with renderer compromise.

Mitigation

Update Google Chrome to version 149.0.7827.197 or later. In enterprise environments, deploy the update via centralized endpoint management and verify adoption across managed devices.

Weakness (CWE)

CWE-346

EPSS Score

0.2%
Probability of exploitation in next 30 days
9.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE