Executive brief
A security vulnerability exists in the Android Autofill component of Google Chrome for Android. This flaw could allow a malicious website to bypass the browser's Same Origin Policy, which is a fundamental security boundary that prevents websites from interacting with data from other sites. If exploited, an attacker could potentially access sensitive information or perform unauthorized actions on behalf of the user across different websites.
Technical details
An inappropriate implementation vulnerability exists in the Android Autofill component of Google Chrome for Android prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by enticing a user to visit a specially crafted HTML page. By exploiting this weakness, an attacker can potentially access data or interact with web content from origins other than the one serving the malicious page. The vulnerability is categorized by Chromium as Low severity and has been addressed in the stable channel update.
Affected products
- Google Chrome for Android prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released for stable channel
- 2026-06-05: disclosed: CVE published in NVD dataset