CVE-2026-6312
vulnerability analysis and mitigation

Overview

CVE-2026-6312 is an insufficient policy enforcement vulnerability in the Passwords feature of Google Chrome that allows a remote attacker who has already compromised the renderer process to leak cross-origin data. It affects Google Chrome versions prior to 147.0.7727.101 and Microsoft Edge (Chromium-based). The vulnerability was reported by Google on March 31, 2026, and publicly disclosed on April 15, 2026, as part of a 31-fix stable channel update. It carries a CVSS v3.1 base score of 3.1 (Low), though Google internally rated it as High severity (Chrome Releases, GitHub Advisory).

Technical details

The root cause is insufficient policy enforcement (CWE-284: Improper Access Control; CWE-346: Origin Validation Error) within Chrome's Passwords component, which fails to properly enforce cross-origin isolation policies when the renderer process has been compromised. An attacker who has already achieved renderer process compromise can exploit this flaw by directing a user to interact with a specially crafted HTML page, causing the Passwords subsystem to improperly expose cross-origin data that should be restricted. The attack requires network access, high complexity (a pre-compromised renderer), no privileges, and user interaction with a malicious page. The Chromium issue tracker entry is referenced as issue 498269651, though full technical details remain restricted pending broad user uptake of the patch (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of cross-origin data accessible through Chrome's Passwords feature, with a low confidentiality impact and no integrity or availability impact. The vulnerability is constrained by the precondition of a pre-compromised renderer process, limiting its standalone impact, but in a chained attack scenario it could contribute to credential theft or exposure of sensitive password-related information stored or processed by the browser. There is no evidence of lateral movement capability or broader system compromise directly attributable to this flaw (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting (GitHub Advisory). The EPSS score is approximately 0.008–0.011%, placing it in the 2nd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. Exploitation requires a chained attack where the renderer process is first compromised via a separate vulnerability, significantly raising the bar for real-world exploitation.

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac), which addresses this vulnerability along with 30 other security fixes. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No configuration-based workaround is available; upgrading to the patched version is the only remediation. Organizations should prioritize browser patching as part of their standard patch management cycle (Chrome Releases, Microsoft MSRC).

Community reactions

The vulnerability was part of a large Chrome security update that received coverage from security news outlets highlighting the broader batch of 31 fixes, including several Critical-rated issues. Coverage from sources such as CyberNoz and CyberPress noted the update's significance due to the presence of critical sandbox escape vulnerabilities in the same release, though CVE-2026-6312 itself was not individually highlighted as a primary concern given its lower CVSS score. The CIS issued an advisory noting that multiple vulnerabilities in the update could allow for arbitrary code execution (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management