Impact
The flaw arises from an inappropriate implementation of the Autofill feature, classified as CWE‑346, that permits a remote attacker who has already compromised the renderer process to leak cross‑origin data through a specially crafted HTML page. This results in a confidentiality loss as sensitive user data may be exposed to an attacker’s web content.
Affected Systems
Google Chrome browsers prior to 149.0.7827.197 on all desktop platforms where Autofill is enabled are affected. This inference is based on the version range in the patch release and typical desktop usage of Autofill.
Risk and Exploitability
Exploitation requires a prior compromise of the renderer process, which generally means a separate vulnerability or successful social engineering. Once the renderer is under attacker control, a malicious webpage can trigger the data leak. The CVSS score of 3.1 indicates a low-to-moderate severity, while an EPSS score of <1% signals a very low likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, so overall risk remains low to moderate, with confidentiality as the primary concern in compromised environments.
OpenCVE Enrichment
Debian DLA
Debian DSA