Описание
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
A flaw was found in Google Chrome's Autofill feature. A remote attacker, after compromising the browser's renderer process, could exploit an inappropriate implementation to leak sensitive data from other websites. This vulnerability is triggered by a specially crafted HTML page, leading to unauthorized information disclosure.
Отчет
This is an Important vulnerability in the Chromium Autofill component. A remote attacker could exploit this flaw, requiring a compromised renderer process and user interaction with a specially crafted HTML page, to leak sensitive cross-origin data. This could lead to significant information disclosure in affected Red Hat products utilizing Chromium.
Дополнительная информация
Статус:
7.4 High
CVSS3
Связанные уязвимости
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-13022 Inappropriate implementation in Autofill
Inappropriate implementation in Autofill in Google Chrome prior to 149 ...
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
7.4 High
CVSS3