Description
Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

Missing authorization in the Autofill feature of Google Chrome allowed a remote attacker to gather sensitive information from a user’s browser through a crafted HTML page, exposing data that should have been protected by proper access controls. The flaw is an instance of unauthorized access (CWE‑862), resulting in potential leakage of private credentials, form data, or payment details.

Affected Systems

Google Chrome browsers on desktop platforms prior to version 155.0.8059.39 were vulnerable. The issue affected the stable channel releases published before the October 2026 update that addressed the missing authorization.

Risk and Exploitability

The vulnerability can be exploited by a remote attacker who social‑engineers a victim into loading a malicious page. No public exploit code is known, and the exploit requires user interaction rather than a purely automated attack. With the Creative Commons medium severity rating and no EPSS spike, the risk remains moderate but non‑negligible, especially for users handling sensitive personal data.

Generated by OpenCVE AI on October 6, 2026 at 21:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 155.0.8059.39 or later
  • Disable or restrict Autofill functionality through Chrome settings or local policy if an update cannot be applied immediately
  • Educate users to avoid clicking suspicious links that might trigger the crafted page

Generated by OpenCVE AI on October 6, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Chrome Autofill Enables Remote Information Retrieval

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:25:51.344Z

Reserved: 2026-10-06T16:32:12.991Z

Link: CVE-2026-106225

cve-icon Vulnrichment

Updated: 2026-10-06T20:17:04.449Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:49.230

Modified: 2026-10-06T21:17:07.107

Link: CVE-2026-106225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:30:07Z

Weaknesses