Impact
A flaw in Google Chrome for Android’s Autofill component allows a malicious renderer to read data from other origins using a specially crafted HTML page. The vulnerability lies in insecure handling ofWE‑346) and failure to protect against cross‑site request forgery (CWE‑352). A remote attacker who can compromise the renderer process can use this flaw to expose sensitive information that was not intended for the page’s origin, resulting in data leakage.
Affected Systems
Devices running Google Chrome for Android version 149.x or earlier, including the stable channel, are affected. Updating to version 150.0.7871.47 or later eliminates the weakness.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires first compromising the renderer process the attacker can retrieve cross‑origin data but cannot directly execute arbitrary code or elevate privileges beyond the renderer.
OpenCVE Enrichment
Debian DLA
Debian DSA