Impact
Insufficient policy enforcement in the Autofill component of Google Chrome on iOS allows a remote attacker to retrieve cross‑origin data through a specially crafted web page. Based on the description, it is inferred that an attacker can inject malicious content that accesses the user’s autofill information and exfiltrate it, compromising the confidentiality of sensitive data. This weakness is categorized as a security misconfiguration (CWE‑693).
Affected Systems
Chromes affected are the Google Chrome browser on iOS devices running versions older than 149.0.7827.53. The issue has been identified only in the stable channel for iOS and applies to all builds prior to the specified version.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating a medium severity rating. The EPSS score is less than 1% and the issue is not listed in the CISA KEV catalog, suggesting limited knowledge of active exploitation. However, exploitation would require the user to load a malicious web page that manipulates Chrome's Autofill policy. Once this condition is met, the attacker could read and exfiltrate stored form data across origins, a direct pathway to leaking credentials or personally identifying information.
OpenCVE Enrichment
Debian DSA