A vulnerability classified as problematic was found in Google Chrome. Affected by this issue is some unknown functionality of the component Autofill. The manipulation results in permissive cross-domain policy with untrusted domains. This vulnerability is identified as CVE-2026-13022. The attack can be executed remotely.
| Vendor | Product | Versions |
|---|---|---|
| chrome | 149.0.7827.197, 149.0.7827.155 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| chrome | cert_advisory | 90% | |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft, added product Edge, and marked exploit as available and actively exploited.
Updated description with new technical details, changed severity to HIGH, and identified affected versions as 149.0.7827.155.
Initial creation