
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6312 is an insufficient policy enforcement vulnerability in the Passwords feature of Google Chrome that allows a remote attacker who has already compromised the renderer process to leak cross-origin data. It affects Google Chrome versions prior to 147.0.7727.101 and Microsoft Edge (Chromium-based). The vulnerability was reported by Google on March 31, 2026, and publicly disclosed on April 15, 2026, as part of a 31-fix stable channel update. It carries a CVSS v3.1 base score of 3.1 (Low), though Google internally rated it as High severity (Chrome Releases, GitHub Advisory).
The root cause is insufficient policy enforcement (CWE-284: Improper Access Control; CWE-346: Origin Validation Error) within Chrome's Passwords component, which fails to properly enforce cross-origin isolation policies when the renderer process has been compromised. An attacker who has already achieved renderer process compromise can exploit this flaw by directing a user to interact with a specially crafted HTML page, causing the Passwords subsystem to improperly expose cross-origin data that should be restricted. The attack requires network access, high complexity (a pre-compromised renderer), no privileges, and user interaction with a malicious page. The Chromium issue tracker entry is referenced as issue 498269651, though full technical details remain restricted pending broad user uptake of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation results in unauthorized disclosure of cross-origin data accessible through Chrome's Passwords feature, with a low confidentiality impact and no integrity or availability impact. The vulnerability is constrained by the precondition of a pre-compromised renderer process, limiting its standalone impact, but in a chained attack scenario it could contribute to credential theft or exposure of sensitive password-related information stored or processed by the browser. There is no evidence of lateral movement capability or broader system compromise directly attributable to this flaw (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting (GitHub Advisory). The EPSS score is approximately 0.008–0.011%, placing it in the 2nd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. Exploitation requires a chained attack where the renderer process is first compromised via a separate vulnerability, significantly raising the bar for real-world exploitation.
Google has released a patch in Chrome stable channel version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac), which addresses this vulnerability along with 30 other security fixes. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No configuration-based workaround is available; upgrading to the patched version is the only remediation. Organizations should prioritize browser patching as part of their standard patch management cycle (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome security update that received coverage from security news outlets highlighting the broader batch of 31 fixes, including several Critical-rated issues. Coverage from sources such as CyberNoz and CyberPress noted the update's significance due to the presence of critical sandbox escape vulnerabilities in the same release, though CVE-2026-6312 itself was not individually highlighted as a primary concern given its lower CVSS score. The CIS issued an advisory noting that multiple vulnerabilities in the update could allow for arbitrary code execution (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."