Executive brief
A vulnerability in the Autofill feature of Google Chrome on Android could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into providing sensitive information or performing unintended actions by overlaying or mimicking legitimate browser prompts. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in the Autofill component of Google Chrome for Android prior to version 150.0.7871.47. The flaw stems from improper input validation (CWE-20) of untrusted data within a crafted HTML page. A remote attacker can exploit this by enticing a user to visit a malicious website, allowing the attacker to manipulate or spoof user interface elements. This can lead to phishing attacks or user confusion regarding the browser's state. The issue is resolved in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched