Описание
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
A flaw was found in Google Chrome's Passwords feature. A remote attacker could exploit this vulnerability by compromising the browser's rendering engine and then using a specially designed web page. This could allow the attacker to bypass security measures designed to isolate websites, potentially leading to unauthorized access to sensitive user data.
Отчет
This is an Important flaw in the Chromium browser's Passwords component. A remote attacker, after compromising the renderer process, could bypass site isolation via a crafted HTML page. This could lead to unauthorized access to sensitive information, such as stored passwords, despite the intended security boundaries of site isolation.
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-13034 Inappropriate implementation in Passwords
Inappropriate implementation in Passwords in Google Chrome prior to 14 ...
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
8.8 High
CVSS3