Executive brief
A vulnerability in the Autofill feature of Google Chrome for Android could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information stored in the browser. Users are advised to update their mobile browser to the latest version to mitigate this risk.
Technical details
A cross-origin data leak vulnerability exists in the Autofill component of Google Chrome for Android prior to version 151.0.7922.72. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries during autofill operations. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, which can then trigger the leak of data belonging to a different origin. This is classified by Chromium as a Medium severity issue. The vulnerability is addressed in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for Android/Desktop
- 2026-07-30: disclosed: CVE published to NVD