Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6312

16
FAUCET Score

CVE-2026-6312 is an insufficient policy enforcement vulnerability in Google Chrome's password manager affecting versions prior to 147.0.7727.101. The flaw allows a remote attacker with access to the compromised renderer process to extract cross-origin data through a specially crafted HTML page. This represents a moderate confidentiality risk classified as High severity by Chromium's security team. The attack requires network access and user interaction, with high complexity, as an attacker must first compromise the renderer process. The impact is limited to low-level confidentiality loss with no integrity or availability impact, reflected in the CVSS 3.1 score of 3.1 (Low). The EPSS score of 0.0001 indicates minimal probability of exploitation in the wild relative to other vulnerabilities. There is no evidence of active exploitation or public exploit code availability. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The overall FAUCET risk score of 27.0 out of 100 suggests this vulnerability poses a low to moderate organizational risk requiring standard patch management procedures.

Impacted Technologies

VendorProductVersion(s)CPE
>= 147.0.7727.101, < 147.0.7727.101CPE match
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
< 147.0.7727.101CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
13.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 41st percentile among its peer group of 233 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 147.0.3912.72
googlevendor investigatingvia chrome_releases
View patch

Vendor Advisories (2)

microsoft2026-Apr/CVE-2026-6312

Chromium: CVE-2026-6312 Insufficient policy enforcement in Passwords

Apr 14, 2026
googlegoogle:chrome-7d655429efb624cbCRITICAL

Stable Channel Update for ChromeOS / ChromeOS Flex

References

chromereleases.googleblog.com / 2026/04/stable-channel-update-for-desktop_15.html
Release NotesVendor Advisory
issues.chromium.org / issues/498269651
Permissions Required