Impact
The vulnerability stems from insufficient validation of untrusted input in the Autofill module of Google Chrome for Android. A crafted HTML page can trigger the browser to render counterfeit form elements that look authentic, enabling a remote attacker to cause users to enter sensitive data into maliciously rendered fields. The core weakness is improper input validation, identified as CWE‑20.
Affected Systems
Google Chrome for Android builds released before version 150.0.7871.47 contain the vulnerable Autofill code and are susceptible when the feature is enabled.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score below 1% implies a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs to entice a user to visit a malicious or compromised web page; no local privileges or device compromise are required. Attack vector is remote via a web page delivering the crafted content.
OpenCVE Enrichment
Debian DLA
Debian DSA