CVE-2026-13022

Description

A flaw was found in Google Chrome's Autofill feature. A remote attacker, after compromising the browser's renderer process, could exploit an inappropriate implementation to leak sensitive data from other websites. This vulnerability is triggered by a specially crafted HTML page, leading to unauthorized information disclosure.

Statement

This is an Important vulnerability in the Chromium Autofill component. A remote attacker could exploit this flaw, requiring a compromised renderer process and user interaction with a specially crafted HTML page, to leak sensitive cross-origin data. This could lead to significant information disclosure in affected Red Hat products utilizing Chromium.

Frequently Asked Questions

Want to get errata notifications? Sign up here.