Executive brief
A vulnerability in Google Chrome's Autofill feature could allow a malicious website to bypass security controls. By tricking a user into visiting a specially crafted webpage, an attacker could potentially access sensitive information that should be protected by the browser's access controls. This could lead to the unauthorized exposure of user data stored within the browser.
Technical details
This vulnerability is classified as insufficient policy enforcement within the Autofill component of Google Chrome. The root cause is a failure to properly validate or enforce discretionary access control (DAC) policies when processing form data. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass security boundaries and potentially access sensitive data handled by the Autofill system. The issue is resolved in Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published to NVD.