Description
Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Google Chrome for Android’s Autofill component allows a malicious renderer to read data from other origins using a specially crafted HTML page. The vulnerability lies in insecure handling ofWE‑346) and failure to protect against cross‑site request forgery (CWE‑352). A remote attacker who can compromise the renderer process can use this flaw to expose sensitive information that was not intended for the page’s origin, resulting in data leakage.

Affected Systems

Devices running Google Chrome for Android version 149.x or earlier, including the stable channel, are affected. Updating to version 150.0.7871.47 or later eliminates the weakness.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires first compromising the renderer process the attacker can retrieve cross‑origin data but cannot directly execute arbitrary code or elevate privileges beyond the renderer.

Generated by OpenCVE AI on July 15, 2026 at 11:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome for Android to version 150.0.7871.47 or later to apply the official fix.
  • If an immediate update is not possible, disable the Autofill feature in the browser settings to prevent cross‑origin data exposure.
  • Verify that the renderer is sand-boxed and that least‑privilege policies are enforced to reduce the risk of renderer compromise.

Generated by OpenCVE AI on July 15, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chromium Autofill Cross‑Origin Data Leak via Compromised Renderer

Tue, 14 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chromium Autofill Cross‑Origin Data Leak via Compromised Renderer

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak in Chrome Autofill via Compromised Renderer

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak in Chrome Autofill via Compromised Renderer

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill Cross‑Origin Data Leakage Vulnerability

Thu, 09 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill Cross‑Origin Data Leakage Vulnerability

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Autofill in Chrome for Android

Tue, 07 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Autofill in Chrome for Android

Mon, 06 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Chrome for Android Autofill Cross-Origin Data Leak

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome for Android Autofill Cross-Origin Data Leak

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill Cross‑Origin Data Leakage via Renderer Compromise

Sat, 04 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill Cross‑Origin Data Leakage via Renderer Compromise

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Chrome Autofill Render Process Compromise

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Chrome Autofill Render Process Compromise

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Android Chrome Autofill Cross‑Origin Data Leakage

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Android Chrome Autofill Cross‑Origin Data Leakage

Thu, 02 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill Cross‑Origin Data Leak via Renderer Compromise

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill Cross‑Origin Data Leak via Renderer Compromise

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Autofill in Chrome for Android
Weaknesses CWE-200

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
CWE-352
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Autofill in Chrome for Android
Weaknesses CWE-200

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Autofill in Google Chrome on Android
Weaknesses CWE-200

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Autofill in Google Chrome on Android
Weaknesses CWE-200

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:13:08.629Z

Reserved: 2026-06-29T23:03:27.222Z

Link: CVE-2026-13826

cve-icon Vulnrichment

Updated: 2026-07-01T15:13:04.585Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T11:15:16Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-352

    Cross-Site Request Forgery (CSRF)