Executive brief
A security vulnerability in Google Chrome's Autofill feature could allow an attacker to access sensitive information from other websites. This occurs when a user visits a specially crafted malicious webpage. If exploited, this could lead to the leakage of personal data or credentials stored in the browser's autofill system.
Technical details
An inappropriate implementation vulnerability exists in the Autofill component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass cross-origin isolation boundaries. By enticing a user to visit a malicious HTML page, the attacker can leak sensitive data across origins. This issue is mitigated by updating to Chrome version 149.0.7827.197 or later. Google classifies this as a High severity issue.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-05-26: disclosed: Reported to Google internally
- 2026-06-23: patched: Fixed in Chrome Stable channel update 149.0.7827.196/197
- 2026-06-24: advisory: NVD publication date