Junglewise Threat Intelligence

CVE-2026-87478: Google Chrome observable discrepancy in Autofill

CVE-2026-87478 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's autofill feature contains a logic flaw that allows remote attackers to detect when autofill data exists for specific fields, even if the data isn't revealed. This enables attackers to infer sensitive information about users (such as email addresses or payment details on file) by crafting a deceptive webpage, potentially compromising user privacy without direct data exposure.

Technical details

This vulnerability is an observable discrepancy in the Autofill component of Google Chrome prior to version 153.0.8010.36. It occurs when a crafted HTML page is able to detect timing or behavioral differences that reveal whether autofill data exists for particular form fields, without actually extracting the data itself. The attack is network-based and requires user interaction (visiting the malicious page). An attacker can infer the presence of sensitive information in a user's autofill database, which aids in social engineering or targeted phishing attacks. The issue is patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats