Executive brief
A vulnerability in Google Chrome's Autofill feature could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information stored in the browser. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
An inappropriate implementation vulnerability exists in the Autofill component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from other origins. The issue is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. This vulnerability is categorized by Chromium as Medium severity.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google released the stable channel update fixing the issue.
- 2026-07-30: disclosed: NVD published the CVE record.