Impact
Insufficient policy enforcement in the Autofill component of Google Chrome on iOS allows a remote attacker to retrieve cross‑origin data through a specially crafted web page. By exploiting this flaw, an attacker can inject malicious content that accesses the user's autofill information and exfiltrate it, compromising the confidentiality of sensitive data. This weakness is categorized as an information exposure flaw (CWE‑200).
Affected Systems
Chromes affected are the Google Chrome browser on iOS devices running versions older than 149.0.7827.53. The issue has been identified only in the stable channel for iOS and applies to all builds prior to the specified version.
Risk and Exploitability
The vulnerability carries a high severity rating as noted by Chromium's internal severity tracking. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog, indicating limited knowledge of active exploitation. However, exploitation would require the user to load a malicious web page that manipulates Chrome's Autofill policy. Once this condition is met, the attacker could read and exfiltrate stored form data across origins, a direct pathway to leaking credentials or personally identifying information.
OpenCVE Enrichment