Google · Google Chrome · CVE-2026-12446
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 149.0.7827.155
**Description**
An inappropriate implementation in the Passwords component allows a remote attacker to leak cross-origin data, which is data from a different domain than the one serving the current page, by using a crafted HTML page.
**Recommendations**
Update to version 149.0.7827.155 or later.