Executive brief
Google Chrome for Android contains a security flaw in its Autofill feature, which helps users automatically fill out web forms. A remote attacker could use a specially crafted website to trick the browser into displaying misleading interface elements. This could be used to deceive users into performing unintended actions or providing information under false pretenses.
Technical details
A UI spoofing vulnerability exists in the Autofill component of Google Chrome for Android prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that allows a remote attacker to manipulate the browser's user interface via a specially crafted HTML page. An attacker could exploit this to present deceptive UI elements to the user, potentially leading to user confusion or social engineering attacks. The vulnerability is triggered when a user visits a malicious site, requiring no special privileges other than standard network access. Google has addressed this issue in the stable channel update for Chrome 150.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched