Description
Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Information disclosure via Autofill
Action: Apply patch
AI Analysis

Impact

CVE-2026-106212 is an incorrect authorization vulnerability in the Autofill component of Google Chrome. When a web page is rendered, the browser does not properly verify that the requester has permission to read stored user data. A remote attacker can therefore use a crafted HTML page, combined with social engineering tactics, to trick a user into opening the page and cause the browser to inadvertently expose sensitive Autofill data. The flaw sits in the boundary between the user interface and credential storage and could be used to retrieve data such as passwords, credit card numbers, or form fields stored by the browser.

Affected Systems

All versions of Google Chrome before 155.0.8059.39 are vulnerable. The issue is fixed in version 155.0.8059.39 and later.

Risk and Exploitability

The vulnerability is rated medium severity by Chromium. No EPSS score is publicly available, and the issue is not listed in the CISA KEV catalog. A potential attacker would need the victim to visit a malicious web page, which is a relatively low effort attack, but the impact is non‑negligible because it can lead to leakage of sensitive personal data. The exploitation vector is a remote, client‑side attack that relies on a victim’s own browser or device.

Generated by OpenCVE AI on October 6, 2026 at 21:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later
  • Ensure Chrome auto‑updates are enabled so future patches are applied automatically
  • As a temporary mitigation, disable the Autofill feature in Chrome’s settings if an update cannot be applied immediately

Generated by OpenCVE AI on October 6, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Autofill Authorization Escalation in Chrome

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:25:50.922Z

Reserved: 2026-10-06T16:31:38.559Z

Link: CVE-2026-106212

cve-icon Vulnrichment

Updated: 2026-10-06T20:16:57.034Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:47.640

Modified: 2026-10-06T21:17:06.570

Link: CVE-2026-106212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses