Executive brief
Google Chrome's Autofill feature contains a logic flaw that allows attackers to detect whether a user has specific sensitive information (such as payment cards or credentials) stored in their browser. By crafting a malicious webpage, an attacker can observe subtle behavioral differences to infer what personal data a target has previously saved, enabling targeted phishing or social engineering attacks.
Technical details
This vulnerability is an information disclosure flaw in Chrome's Autofill subsystem, classified as an observable discrepancy (CWE-436). The defect lies in how Autofill responds to or behaves when processing form fields—differences in timing, DOM state, or UI feedback reveal whether stored autofill data exists for a given user. The attack requires only a crafted HTML page served over the network; no user authentication or special privileges are needed. A remote attacker can use this to infer which sensitive financial or identity data a visitor has saved, facilitating account takeover or credential theft campaigns. The vulnerability was patched in Chrome 152.0.7977.65 (released August 25, 2026).
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65