Impact
Missing authorization in the Autofill feature of Google Chrome allowed a remote attacker to gather sensitive information from a user’s browser through a crafted HTML page, exposing data that should have been protected by proper access controls. The flaw is an instance of unauthorized access (CWE‑862), resulting in potential leakage of private credentials, form data, or payment details.
Affected Systems
Google Chrome browsers on desktop platforms prior to version 155.0.8059.39 were vulnerable. The issue affected the stable channel releases published before the October 2026 update that addressed the missing authorization.
Risk and Exploitability
The vulnerability can be exploited by a remote attacker who social‑engineers a victim into loading a malicious page. No public exploit code is known, and the exploit requires user interaction rather than a purely automated attack. With the Creative Commons medium severity rating and no EPSS spike, the risk remains moderate but non‑negligible, especially for users handling sensitive personal data.
OpenCVE Enrichment