Executive brief
A vulnerability in Google Chrome's Autofill feature could allow a malicious website to access data from other websites you visit. This occurs when the browser incorrectly handles how it fills in forms, potentially leading to the exposure of sensitive user information. Users are advised to update their browser to the latest version to prevent this unauthorized data access.
Technical details
A cross-origin data leak vulnerability exists in the Autofill component of Google Chrome prior to version 151.0.7922.72. The flaw stems from an inappropriate implementation of form-filling logic, which fails to strictly enforce origin boundaries. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to capture data that should be restricted to other origins. This issue is categorized by Chromium as Medium severity and has been addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date