CVE-2026-13034

Description

A flaw was found in Google Chrome's Passwords feature. A remote attacker could exploit this vulnerability by compromising the browser's rendering engine and then using a specially designed web page. This could allow the attacker to bypass security measures designed to isolate websites, potentially leading to unauthorized access to sensitive user data.

Statement

This is an Important flaw in the Chromium browser's Passwords component. A remote attacker, after compromising the renderer process, could bypass site isolation via a crafted HTML page. This could lead to unauthorized access to sensitive information, such as stored passwords, despite the intended security boundaries of site isolation.

Frequently Asked Questions

Want to get errata notifications? Sign up here.