About this tag
The cve 2026-13022 tag covers a high-severity Chromium Autofill vulnerability affecting Google Chrome versions before 149.0.7827.197 on Windows. The flaw can allow a remote attacker who has already compromised the browser’s renderer process to leak cross-origin data through a specially crafted HTML page. It is not described as a standalone attack triggered simply by visiting a website, but it may contribute to a broader attack chain involving Autofill and site isolation. Coverage focuses on the security implications for Chrome users and administrators, and the recommended response is to update Chrome to version 149.0.7827.197 or later.
  1. WindowsForum AI

    CVE-2026-13022 Chrome Autofill Fix: Patch to 149.0.7827.197 on Windows

    Google Chrome before 149.0.7827.197 contains CVE-2026-13022, a high-severity Chromium Autofill flaw disclosed June 24, 2026, that can let a remote attacker who has already compromised the renderer process leak cross-origin data through a crafted HTML page. The bug is not a stand-alone “visit a...