Junglewise Threat Intelligence

CVE-2026-84327: Google Chrome Autofill incorrect authorization in Android

CVE-2026-84327 · Severity: medium · CVSS 6.5 · Published 2026-09-02

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's Autofill feature on Android contains an authorization flaw that allows attackers to trick users into revealing sensitive information through deceptively crafted web pages. An attacker could exploit this via social engineering to obtain user credentials or personal data that Chrome's Autofill feature normally stores and manages.

Technical details

The vulnerability is an incorrect authorization issue in the Autofill component of Google Chrome for Android. It allows a remote attacker to bypass authorization checks and obtain sensitive information through a crafted HTML page combined with social engineering tactics. No authentication is required—only that the user visits a malicious webpage and interacts with it. The attack vector is network-based, requiring user interaction. The issue affects Chrome versions prior to 152.0.7977.75 on Android, and patches are available in the indicated version and later.

Affected products

  • Google Chrome prior to 152.0.7977.75 on Android

Timeline

  • 2026-09-02: disclosed

References

Related threats