Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13022

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 7.4

Описание

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome's Autofill feature. A remote attacker, after compromising the browser's renderer process, could exploit an inappropriate implementation to leak sensitive data from other websites. This vulnerability is triggered by a specially crafted HTML page, leading to unauthorized information disclosure.

Отчет

This is an Important vulnerability in the Chromium Autofill component. A remote attacker could exploit this flaw, requiring a compromised renderer process and user interaction with a specially crafted HTML page, to leak sensitive cross-origin data. This could lead to significant information disclosure in affected Red Hat products utilizing Chromium.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2492500Chromium-browser: Chromium Autofill: Information disclosure via crafted HTML page after renderer compromise

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

msrc
около 2 месяцев назад

Chromium: CVE-2026-13022 Inappropriate implementation in Autofill

CVSS3: 6.5
debian
около 2 месяцев назад

Inappropriate implementation in Autofill in Google Chrome prior to 149 ...

CVSS3: 6.5
github
около 2 месяцев назад

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

7.4 High

CVSS3