CVE-2026-13022
Description
A flaw was found in Google Chrome's Autofill feature. A remote attacker, after compromising the browser's renderer process, could exploit an inappropriate implementation to leak sensitive data from other websites. This vulnerability is triggered by a specially crafted HTML page, leading to unauthorized information disclosure.
Statement
This is an Important vulnerability in the Chromium Autofill component. A remote attacker could exploit this flaw, requiring a compromised renderer process and user interaction with a specially crafted HTML page, to leak sensitive cross-origin data. This could lead to significant information disclosure in affected Red Hat products utilizing Chromium.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.