Junglewise Threat Intelligence

CVE-2026-79288: Google Chrome improper input validation in Autofill

CVE-2026-79288 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's Autofill feature on Android contains an input validation vulnerability that allows attackers to access sensitive user information through a malicious HTML webpage. An attacker could harvest autofilled data such as credentials, payment information, or personal details by crafting a specially designed web page that tricks Chrome's autofill mechanism. This affects Android users running Chrome versions before 152.0.7977.65.

Technical details

CVE-2026-79288 is an improper input validation vulnerability in Google Chrome's Autofill component on Android. The root cause lies in insufficient validation of HTML input fields, allowing a remote attacker to bypass autofill security mechanisms and extract sensitive data. The attack vector is network-based, requiring only that a user visit a crafted HTML page—no authentication or special privileges are needed. An attacker can obtain sensitive information such as stored credentials, payment card data, or personal details populated via autofill. The vulnerability is fixed in Chrome 152.0.7977.65 and later for Android.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-06-14: disclosed: Vulnerability reported to Google
  • 2026-08-25: patched: Chrome 152.0.7977.65 released with fix for Android

References

Related threats