Executive brief
A vulnerability in Google Chrome's Autofill feature could allow a malicious website to steal information from other websites. To succeed, an attacker must trick a user into performing specific interactions, such as clicking or typing, on a specially crafted webpage. This could result in the unauthorized disclosure of sensitive user data across different web domains.
Technical details
A side-channel information leakage vulnerability (CWE-1300) exists in the Autofill component of Google Chrome prior to version 151.0.7922.72. The flaw allows a remote attacker to bypass cross-origin isolation by convincing a user to perform specific UI gestures on a malicious HTML page. By observing side-channel signals during these interactions, the attacker can leak data from different origins. The vulnerability is addressed in the Chrome stable channel update 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date