Executive brief
Google Chrome's Forms component contains a flaw that allows attackers to detect differences in how form fields are processed, potentially exposing sensitive information about web page content. By sending specially crafted HTML pages, remote attackers can infer information about form data or page structure without requiring any user interaction or authentication, creating a privacy risk for end users browsing the web.
Technical details
This vulnerability is an observable discrepancy (timing or behavioral side-channel) in Chrome's Forms handling that allows information disclosure. The vulnerability affects Chrome versions prior to 152.0.7977.65 and is triggered via a crafted HTML page delivered over the network. An attacker can exploit this by hosting malicious web content that probes form behavior to infer sensitive information. The attack requires no user authentication or special privileges—only network reachability to send the crafted HTML. Chrome 152.0.7977.65 and later versions contain the fix.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65