Impact
CVE-2026-106212 is an incorrect authorization vulnerability in the Autofill component of Google Chrome. When a web page is rendered, the browser does not properly verify that the requester has permission to read stored user data. A remote attacker can therefore use a crafted HTML page, combined with social engineering tactics, to trick a user into opening the page and cause the browser to inadvertently expose sensitive Autofill data. The flaw sits in the boundary between the user interface and credential storage and could be used to retrieve data such as passwords, credit card numbers, or form fields stored by the browser.
Affected Systems
All versions of Google Chrome before 155.0.8059.39 are vulnerable. The issue is fixed in version 155.0.8059.39 and later.
Risk and Exploitability
The vulnerability is rated medium severity by Chromium. No EPSS score is publicly available, and the issue is not listed in the CISA KEV catalog. A potential attacker would need the victim to visit a malicious web page, which is a relatively low effort attack, but the impact is non‑negligible because it can lead to leakage of sensitive personal data. The exploitation vector is a remote, client‑side attack that relies on a victim’s own browser or device.
OpenCVE Enrichment