Impact
A flaw in Google Chrome for Android’s Autofill component allows a malicious renderer to read data from other origins using a specially crafted HTML page. The vulnerability lies in insecure handling of CWE-346 and failure to protect against cross‑site request forgery (CWE-352). A remote attacker who can compromise the renderer process can use this flaw to expose sensitive information that was not intended for the page’s origin, resulting in data leakage.
Affected Systems
Devices running Google Chrome for Android prior to version 150.0.7871.47 may be affected. Updating to that version or later eliminates the weakness.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires first compromising the renderer process; the attacker then can retrieve cross‑origin data but cannot directly execute arbitrary code or elevate privileges beyond the renderer.
OpenCVE Enrichment
Debian DLA
Debian DSA