Junglewise Threat Intelligence

CVE-2026-79030: Google Chrome observable discrepancy in Autofill

CVE-2026-79030 · Severity: medium · CVSS 5.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Autofill feature contains a logic flaw that allows attackers to detect whether a user has specific sensitive information (such as payment cards or credentials) stored in their browser. By crafting a malicious webpage, an attacker can observe subtle behavioral differences to infer what personal data a target has previously saved, enabling targeted phishing or social engineering attacks.

Technical details

This vulnerability is an information disclosure flaw in Chrome's Autofill subsystem, classified as an observable discrepancy (CWE-436). The defect lies in how Autofill responds to or behaves when processing form fields—differences in timing, DOM state, or UI feedback reveal whether stored autofill data exists for a given user. The attack requires only a crafted HTML page served over the network; no user authentication or special privileges are needed. A remote attacker can use this to infer which sensitive financial or identity data a visitor has saved, facilitating account takeover or credential theft campaigns. The vulnerability was patched in Chrome 152.0.7977.65 (released August 25, 2026).

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats