CVE-2026-6312 is an insufficient policy enforcement vulnerability in Google Chrome's password manager affecting versions prior to 147.0.7727.101. The flaw allows a remote attacker with access to the compromised renderer process to extract cross-origin data through a specially crafted HTML page. This represents a moderate confidentiality risk classified as High severity by Chromium's security team. The attack requires network access and user interaction, with high complexity, as an attacker must first compromise the renderer process. The impact is limited to low-level confidentiality loss with no integrity or availability impact, reflected in the CVSS 3.1 score of 3.1 (Low). The EPSS score of 0.0001 indicates minimal probability of exploitation in the wild relative to other vulnerabilities. There is no evidence of active exploitation or public exploit code availability. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The overall FAUCET risk score of 27.0 out of 100 suggests this vulnerability poses a low to moderate organizational risk requiring standard patch management procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.