Junglewise Threat Intelligence

CVE-2026-13826: Google Chrome Autofill cross-origin data leak on Android

CVE-2026-13826 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android contains a security flaw in its Autofill feature, which is used to automatically complete web forms with saved user information. An attacker who has already partially compromised the browser's internal processes could use this flaw to steal sensitive data from other websites the user visits. This could lead to the exposure of personal information or login credentials across different web services.

Technical details

A vulnerability classified as 'Inappropriate Implementation' exists in the Autofill component of Google Chrome on Android prior to version 150.0.7871.47. The flaw allows a remote attacker who has already compromised the renderer process to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a specially crafted HTML page, the attacker can leak cross-origin data. This vulnerability is rated as High severity by Chromium. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-14: disclosed: Reported to Chromium by Google researchers
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats